Answer in brief
CVE-2026-89658 records a Unknown severity vulnerability in NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=d688d8585e6bea5e4e37f7497feea93b6b0a469c <0ae0d2b5c5a1b39c0b3c15d96b32a5b0c583d519 || >=d688d8585e6bea5e4e37f7497feea93b6b0a469c <b413ec5b23e3445dc9c4f273116078e2d4747626 || >=d688d8585e6bea5e4e37f7497feea93b6b0a469c <81cf7f1413862f87b078920c838460a6a88aa030 || >=d688d8585e6bea5e4e37f7497feea93b6b0a469c <7b4f8a1586c42d3afc3c0ac779af2db7ab1a5c55 | 0ae0d2b5c5a1b39c0b3c15d96b32a5b0c583d519, b413ec5b23e3445dc9c4f273116078e2d4747626, 81cf7f1413862f87b078920c838460a6a88aa030, 7b4f8a1586c42d3afc3c0ac779af2db7ab1a5c55 |
| Linux/Linuxgeneric | 6.9 | Not reported |
Published upstream
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 11, 2026
In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup nfs40_clean_admin_revoked() takes a stateid reference under clp->cl_lock, drops nn->client_lock, and calls nfsd4_drop_revoked_stid(), which dereferences the stateid's client through s->sc_client->cl_lock. The stateid reference does not pin the client, so a teardown racing the dropped lock can free the client while nfsd4_drop_revoked_stid() is still using it. This cleanup runs from the laundromat, so a periodic sweep can race force_expire_client() driven by a write to the clients/<id>/ctl file. Skip a client that is already expiring and otherwise pin it with cl_rpc_users under client_lock before dropping the lock, matching nfsd4_revoke_states().
Quoted source text, attributed separately from HOL analysis.