Local Kernel Vulnerability in Linux Kernel Impacting NFSD Services
CVE-2026-90039

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-90039?

A vulnerability in the Linux kernel's Network File System (NFS) services, particularly within the NFSD components, can lead to a local denial of service. When an administrator attempts to revoke open states or cancel asynchronous operations by using specific commands or modifying the NFS filesystem, it can inadvertently trigger a NULL pointer dereference. This occurs due to the improper sequence of initialization and service creation in the NFSD setup. If exploited, this vulnerability can cause kernel crashes, potentially allowing a local administrator with elevated permissions to disrupt server operations without needing to start the server itself. The issue has been addressed by ensuring that necessary safeguards are in place during the service's startup sequence, preventing unauthorized access and system instability.

Affected Version(s)

Linux 1ac3629bf012592cb0320e52a1cceb319a05ad17 < 104a51265042b4424085741c963cb858ac29ec0b

Linux 1ac3629bf012592cb0320e52a1cceb319a05ad17 < 0146467a2fce845cb6629979c3e9c58dd3d3a6a3

Linux 1ac3629bf012592cb0320e52a1cceb319a05ad17 < 2f3e6638aebc0ab8afb8b4e9816ea9a1cad85378

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.