Answer in brief
CVE-2026-89660 records a Unknown severity vulnerability in NFSD: Prevent client use-after-free during admin state revocation. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1c13bf9f2e3cd5a59ef988c6c5a49fe0f02bcdfc <549bd9868e9d77b07ea94870940d64342829c6ad || >=1c13bf9f2e3cd5a59ef988c6c5a49fe0f02bcdfc <bf1f948691523282cc4905bc6cd325e0c0b49e6a || >=1c13bf9f2e3cd5a59ef988c6c5a49fe0f02bcdfc <e270e5a0778e5bff852c8862ce9576ce70359393 | 549bd9868e9d77b07ea94870940d64342829c6ad, bf1f948691523282cc4905bc6cd325e0c0b49e6a, e270e5a0778e5bff852c8862ce9576ce70359393 |
| Linux/Linuxgeneric | 6.9 | Not reported |
Published upstream
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 11, 2026
In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during admin state revocation A stateid holds only a bare pointer to its nfs4_client; a stateid reference does not pin it. The client survives only because __destroy_client() drains its stateids before free_client() runs. nfsd4_revoke_states() drops nn->client_lock across revoke_one_stid(), which dereferences the client to revoke a stateid and read clp->cl_minorversion. A teardown racing the dropped lock can free the client first. Pinning cl_rpc_users under client_lock blocks the DESTROY_CLIENTID and EXCHANGE_ID teardown, which refuses while cl_rpc_users is non-zero. force_expire_client() ignores it: once its wait for cl_rpc_users to reach zero has passed, a later pin goes unnoticed. Under client_lock, skip a client whose cl_time is already zero -- force_expire_client() clears it there before waiting -- otherwise pin cl_rpc_users before dropping the lock. The walk then either sees the expiry and skips, or pins in time for that wait to cover the revoke.
Quoted source text, attributed separately from HOL analysis.