CVE-2026-89703
In the Linux kernel, the following vulnerability has been resolved:
nfsd: set SCSTATUSFREED in nfsd4droprevoked_stid for delegations
nfsd4droprevokedstid() handles FREESTATEID for admin-revoked
delegations but does not set SCSTATUSFREED before releasing cl_lock.
revokedelegation() uses this flag to detect whether FREESTATEID has
already processed the delegation -- without it, the freed delegation is
added to clrevoked via listadd(), producing a use-after-free when
clrevoked is later traversed in destroyclient().
The SCSTATUSREVOKED path in nfsd4freestateid() (line 7983) already
sets SCSTATUSFREED correctly. Apply the same pattern to the
SCSTATUSADMINREVOKED path in nfsd4droprevokedstid().
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/1e4795766719ffd74b8cf0f2fde4a1350f8326bf, https://git.kernel.org/stable/c/650d370cfbc66a96dd14d517bd704689b5bda4e5, https://git.kernel.org/stable/c/a6d89032e5c6620d5bb44582a72555ce07bf1c2e, https://git.kernel.org/stable/c/d832a0587528853d45481d1faf75d4b5d062adaf, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89703.json, https://nvd.nist.gov/vuln/detail/CVE-2026-89703, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git