CVE-2026-89712
In the Linux kernel, the following vulnerability has been resolved:
NFSD: restart sscexpireumount walk after dropping nfsdssclock
nfsd4sscexpireumount() walks nn->nfsdsscmountlist with
listforeachentrysafe(ni, tmp, ...). For each expired entry it
sets nsuibusy = true, drops nfsdssc_lock to run mntput() on the
source vfsmount, then reacquires the lock to list_del + kfree the
entry and continue iterating via the macro's saved tmp pointer.
The nsui_busy flag protects the current ni from concurrent
nfsd4sscsetup_dul() finders during the lock-drop window, but it
does not pin tmp. Another nfsd RPC thread that fails its source-
server mount and reaches nfsd4ssccancel_dul() will, during that
same window, take nfsdssclock, listdel + kfree its own sscumount
item, and release the lock. If that item is the saved tmp of the
expire walk, the next iteration dereferences a freed
nfsd4sscumount_item.
Restart the walk from the head after the mntput() unlock window so
no saved next pointer survives the lock-drop. The list is bounded
by the number of active inter-server source mounts (typically small)
and the expire delayed-work runs periodically rather than per-IO,
so the restart is cheap.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/036c1b182f4da65363e79ec0ac276edc6b7296e5, https://git.kernel.org/stable/c/2b59029b8f24a99b5d844af2da3950d39d36eeea, https://git.kernel.org/stable/c/4ed8d2317aef21cc2a9e5a55d6b59860b4b151a8, https://git.kernel.org/stable/c/60680ae7243b22de3d09be990d8e23bcfc4af837, https://git.kernel.org/stable/c/659ee3da073164e1e6e40dfcbc26eeed85845f93, https://git.kernel.org/stable/c/7377fa964b8aaf47cb04e5efcc4c82d15e8c2ce9, https://git.kernel.org/stable/c/77de363d9a1c8cd35f20482782c612cda085791a, https://git.kernel.org/stable/c/d9e151fea5ed706c1284adacabd869b0be745db2, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89712.json, https://nvd.nist.gov/vuln/detail/CVE-2026-89712, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git