CVE-2026-89658
In the Linux kernel, the following vulnerability has been resolved:
NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup
nfs40cleanadmin_revoked() takes a stateid reference under
clp->cllock, drops nn->clientlock, and calls
nfsd4droprevoked_stid(), which dereferences the stateid's client
through s->scclient->cllock. The stateid reference does not pin the
client, so a teardown racing the dropped lock can free the client
while nfsd4droprevoked_stid() is still using it.
This cleanup runs from the laundromat, so a periodic sweep can race
forceexpireclient() driven by a write to the clients/<id>/ctl file.
Skip a client that is already expiring and otherwise pin it with
clrpcusers under client_lock before dropping the lock, matching
nfsd4revokestates().
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/0ae0d2b5c5a1b39c0b3c15d96b32a5b0c583d519, https://git.kernel.org/stable/c/7b4f8a1586c42d3afc3c0ac779af2db7ab1a5c55, https://git.kernel.org/stable/c/81cf7f1413862f87b078920c838460a6a88aa030, https://git.kernel.org/stable/c/b413ec5b23e3445dc9c4f273116078e2d4747626, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89658.json, https://nvd.nist.gov/vuln/detail/CVE-2026-89658, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git