Use-After-Free Vulnerability in Linux Kernel Affects NFS Client Management
CVE-2026-90036
What is CVE-2026-90036?
A use-after-free vulnerability exists in the Linux kernel's NFS client management system. When a bare lock owner remains as the only reference during blocked-lock reaping, it can potentially lead to dereferencing freed memory. This occurs because the process may free the client before properly managing the lock references, which can cause security risks by allowing unauthorized access to invalid memory. The flaw has been addressed with updates that ensure proper locking mechanisms are in place to manage references correctly.
Affected Version(s)
Linux 7919d0a27f1e7cb324e023776aa1cbff00f1ee7b
Linux 7919d0a27f1e7cb324e023776aa1cbff00f1ee7b < 6fedb2eaff77554ca7a0deffd2e8bc0d6e8b38b0
Linux 7919d0a27f1e7cb324e023776aa1cbff00f1ee7b < 9026932ac8be4d0ae01db47f23619a98cc57b671