DEBIAN-CVE-2026-89658
In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup nfs40cleanadminrevoked() takes a stateid reference under clp->cllock, drops nn->clientlock, and calls nfsd4droprevokedstid(), which dereferences the stateid's client through s->scclient->cllock. The stateid reference does not pin the client, so a teardown racing the dropped lock can free the client while nfsd4droprevokedstid() is still using it. This cleanup runs from the laundromat, so a periodic sweep can race forceexpireclient() driven by a write to the clients/<id>/ctl file. Skip a client that is already expiring and otherwise pin it with clrpcusers under clientlock before dropping the lock, matching nfsd4revokestates().
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://security-tracker.debian.org/tracker/CVE-2026-89658