CVE-2026-89659
In the Linux kernel, the following vulnerability has been resolved:
NFSD: Prevent client use-after-free during delegation revoke
A delegation stateid holds only a bare pointer to its owning
nfs4_client and does not keep it alive. The client survives its
stateids only because _destroyclient() drains cl_delegations and
clrevoked before freeclient() runs.
nfs4_laundromat() breaks that invariant: it unhashes an
expired delegation from cldelegations, drops deleglock, then
revokedelegation() relinks it onto clrevoked under cl_lock. In that
window the delegation is on neither list, so clienthasstate() can
report no remaining state.
Every teardown path first requires clrpcusers to be zero, but
the laundromat holds no such reference. A client whose recalled
delegation has just timed out can therefore reach free_client()
while revokedelegation() is still about to dereference cllock,
a use-after-free.
Pin the client with clrpcusers across the revoke so teardown blocks
until it completes, then reap the delegation from cl_revoked. A client
already expiring reaps its own, so skip it and leave the delegation on
delrecalllru.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/0dd276b1324a5e08e83c6f675919946c9f0d61c9, https://git.kernel.org/stable/c/2a9d637c2a8fd8ac29ad9b29f28d122ef75c1a56, https://git.kernel.org/stable/c/3c0a53ee0b442348d8d2286d6960d3f07bb3a3d3, https://git.kernel.org/stable/c/4683ca76b3b7e5808338491c6eb3c20e6b4894d5, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89659.json, https://nvd.nist.gov/vuln/detail/CVE-2026-89659, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git