Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-89708

nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown
Back to all
CVE

CVE-2026-89708

nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown

In the Linux kernel, the following vulnerability has been resolved:

nfsd: RCU-protect clcbsession to fix use-after-free on session teardown

After a DESTROY_SESSION the per-session teardown path can free a

session while rpciod still holds an inflight callback rpc_task that

dereferences clp->clcbsession.  nfsd4probecallback_sync() flushes

clcallbackwq, but once nfsd4runcb_work() has called

rpccallasync() the rpc_task lives on rpciod; flushing the workqueue

does not wait for it.  rpcshutdownclient() does drain rpciod tasks,

but uses a 1-second waiteventtimeout — tasks stuck in rpc_delay()

(e.g. 2-second NFS4ERR_DELAY retries) can outlive the drain.

    destroy path                       rpciod

    ------------                       ------

    unhash_session(ses)

    nfsd4probecallback_sync(clp)

      flushworkqueue(clcallback_wq)

      / returns; rpc_task still live /

    nfsd4putsession_locked(ses)

    free_session(ses) -> kfree(ses)

                                       nfsd4cbsequence_done()

                                         reads cbclp->clcb_session

                                         / freed slab /

A second window exists in nfsd4processcb_update().  When

_nfsd4findbackchannel() returns NULL because unhashsession() has

already removed the destroyed session from cl_sessions,

setupcallbackclient() takes the v4.1 early return so

clp->clcbsession = ses never fires and the field retains a pointer

to the about-to-be-freed session.

Fix both by converting clcbsession to an RCU-protected pointer:

  • Move the clcbsession = ses assignment in setupcallbackclient()

    to after rpc_create() succeeds, so it is only published when a

    working backchannel exists.  Clear clcbsession on the error

    return in nfsd4processcb_update().  Both stores use

    rcuassignpointer().

  • Annotate clcbsession with __rcu.  All rpciod-side readers use

    rcureadlock()/rcu_dereference() and check for NULL, bailing to

    the appropriate error or requeue path:

    encodecbsequence4args(), decodecbsequence4resok(),

    nfsd41cbgetslot(), nfsd41cbreleaseslot(),

    nfsd4cbprepare(), and nfsd4cbsequence_done().

  • Switch _freesession() from kfree() to kfree_rcu() so the

    session slab is not reclaimed until after an RCU grace period,

    guaranteeing that rpciod readers inside rcureadlock() never

    dereference freed memory.

  • Pass the session pointer to the nfsdcbseq_status and

    nfsdcbfree_slot tracepoints instead of having them re-read

    clcbsession.

  • nfsd4cbprepare() calls rpc_exit() when the session is NULL,

    routing through the done/release path to requeue the callback.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/01c5d5f58a5db9b0ee5afba2e49d3157788687b2, https://git.kernel.org/stable/c/13bdd486c3aad4fc19e6d8b9c3556a4b4c190b25, https://git.kernel.org/stable/c/2775ec1d617e665eab71ce0f13ab1f7959713a2b, https://git.kernel.org/stable/c/f164eb52b6f3cbf40f07fe379f9f421f88e02f76, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89708.json, https://nvd.nist.gov/vuln/detail/CVE-2026-89708, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00444%
EPSS Percentile
0.36632%
Introduced Version
dcbeaa68dbbdacbbb330a86c7fc95a28473fc209,2.6.38,6.13.0,6.19.0,0
Fix Available
01c5d5f58a5db9b0ee5afba2e49d3157788687b2,6.12.111,6.18.50,7.2.4,6.12.111-1~deb12u1,6.12.111-1,0:6.12.0-207.111.5.1.el10uek,0:6.12.0-207.111.5.1.el9uek

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading