Local Kernel Vulnerability in Linux Kernel Impacting NFSD Services
CVE-2026-90039
What is CVE-2026-90039?
A vulnerability in the Linux kernel's Network File System (NFS) services, particularly within the NFSD components, can lead to a local denial of service. When an administrator attempts to revoke open states or cancel asynchronous operations by using specific commands or modifying the NFS filesystem, it can inadvertently trigger a NULL pointer dereference. This occurs due to the improper sequence of initialization and service creation in the NFSD setup. If exploited, this vulnerability can cause kernel crashes, potentially allowing a local administrator with elevated permissions to disrupt server operations without needing to start the server itself. The issue has been addressed by ensuring that necessary safeguards are in place during the service's startup sequence, preventing unauthorized access and system instability.
Affected Version(s)
Linux 1ac3629bf012592cb0320e52a1cceb319a05ad17 < 104a51265042b4424085741c963cb858ac29ec0b
Linux 1ac3629bf012592cb0320e52a1cceb319a05ad17 < 0146467a2fce845cb6629979c3e9c58dd3d3a6a3
Linux 1ac3629bf012592cb0320e52a1cceb319a05ad17 < 2f3e6638aebc0ab8afb8b4e9816ea9a1cad85378