DEBIAN-CVE-2026-89703
In the Linux kernel, the following vulnerability has been resolved: nfsd: set SCSTATUSFREED in nfsd4droprevokedstid for delegations nfsd4droprevokedstid() handles FREESTATEID for admin-revoked delegations but does not set SCSTATUSFREED before releasing cllock. revokedelegation() uses this flag to detect whether FREESTATEID has already processed the delegation -- without it, the freed delegation is added to clrevoked via listadd(), producing a use-after-free when clrevoked is later traversed in destroyclient(). The SCSTATUSREVOKED path in nfsd4freestateid() (line 7983) already sets SCSTATUSFREED correctly. Apply the same pattern to the SCSTATUSADMINREVOKED path in nfsd4droprevokedstid().
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://security-tracker.debian.org/tracker/CVE-2026-89703