Use-After-Free Vulnerability in Linux Kernel's NFSD Component
CVE-2026-90038

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-90038?

A use-after-free vulnerability has been identified in the NFSD component of the Linux kernel. This issue arises during the export state revocation process. When an administrator removes an export, the associated locking mechanism may drop the client lock prematurely. This situation can allow a client to be freed even while its state is being dereferenced, creating a race condition. By implementing proper client pinning under the client lock before releasing it, the vulnerability can be mitigated, preventing potential unauthorized access or instability in the system.

Affected Version(s)

Linux 2eac189bb059d31a29937b29ee0f477394198610

Linux 2eac189bb059d31a29937b29ee0f477394198610 < 2108de53568a64936a0da3e04d85c35df98d3fb6

Linux 7.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.