From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D65B158B6B7 for ; Fri, 11 Sep 2026 20:01:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156882; cv=none; b=YxXpw1LrqJTzV7dOsGZIxXnK4HCWRqqNKFXsw+qqvjJt/80CpfygvbUkMGXyvKTLrbU2bwtJlXPDZN3wBJ32UXRm0rcGdpqEW1CaT+KXIrQbVL4dA1JngPm/MdFNAW5ITAZqeTG1Snmt+0Eaa66I/ZwXD44uIrHOLzcxhc1nsNI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156882; c=relaxed/simple; bh=CI2n80ShB5rrYWlYPqROMAAh1cHm2br10zEDS25FvnA=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=t0BXYg73OMnknxeSrbiLpXii78NuVOuq/JwQDsOFiaD8tMX0agVjkF/NIziBS1cCut5yb/znM7kb+eIiDSPm9GVHEefXmmkpAqmoHNJ1+5Nm1dcxXb/j7soNX88Y/qA+wMB1v06tqiZupCjMJvN6eB0VTYPLZRtEpz6/nSKj+s4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=oPVBavYl; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="oPVBavYl" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 22F651F00893; Fri, 11 Sep 2026 20:01:10 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156871; bh=UKSJqI67I6up9xApcBO+eWaLkw/n/nfoLmSD1Ccywhc=; h=From:To:Cc:Subject:Date:Reply-To; b=oPVBavYlM9dSYiUfki9xzTS6MN0Vhwh6Pru1YEgj69jW7rd+cGzwRHRs7hQ1PsfmH VKP346/dMpx0i83hWujDMTpbgG3BK1T3pgN4V+jglem7WlK0jk2I4b+g1CU/QvSJ0q T+kTPtwhkq1feZahm/qYaxh6BckefE6/Xh9xIMWY= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89659: NFSD: Prevent client use-after-free during delegation revoke Date: Fri, 11 Sep 2026 21:45:48 +0200 Message-ID: <2026091146-CVE-2026-89659-32e5@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3055; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=pC6XQde9m4B+QuCzCINJcD9tybuUvM9VJgVOFrioFhk=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIquK7R5bZC8yCHT7H/tSadupdUunibx7s+Evo48M6 yGmXbebO2JZGASZGGTFFFm+bOM5ur/ikKKXoe1pmDmsTCBDGLg4BWAiqwoY5ocnsShXsZ4wKU7Z tTCQ7e0eh1szmhgWnA4Iu1U666NG+ePd5eGv/gl8XWjCAQA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during delegation revoke A delegation stateid holds only a bare pointer to its owning nfs4_client and does not keep it alive. The client survives its stateids only because __destroy_client() drains cl_delegations and cl_revoked before free_client() runs. nfs4_laundromat() breaks that invariant: it unhashes an expired delegation from cl_delegations, drops deleg_lock, then revoke_delegation() relinks it onto cl_revoked under cl_lock. In that window the delegation is on neither list, so client_has_state() can report no remaining state. Every teardown path first requires cl_rpc_users to be zero, but the laundromat holds no such reference. A client whose recalled delegation has just timed out can therefore reach free_client() while revoke_delegation() is still about to dereference cl_lock, a use-after-free. Pin the client with cl_rpc_users across the revoke so teardown blocks until it completes, then reap the delegation from cl_revoked. A client already expiring reaps its own, so skip it and leave the delegation on del_recall_lru. The Linux kernel CVE team has assigned CVE-2026-89659 to this issue. Affected and fixed versions =========================== Issue introduced in 3.10 with commit 3bd64a5ba1719c2bb6cba4493dfd3e23a7653e54 and fixed in 6.18.51 with commit 3c0a53ee0b442348d8d2286d6960d3f07bb3a3d3 Issue introduced in 3.10 with commit 3bd64a5ba1719c2bb6cba4493dfd3e23a7653e54 and fixed in 7.2.4 with commit 2a9d637c2a8fd8ac29ad9b29f28d122ef75c1a56 Issue introduced in 3.10 with commit 3bd64a5ba1719c2bb6cba4493dfd3e23a7653e54 and fixed in 7.3-rc1 with commit 4683ca76b3b7e5808338491c6eb3c20e6b4894d5 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89659 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: fs/nfsd/netns.h fs/nfsd/nfs4state.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/3c0a53ee0b442348d8d2286d6960d3f07bb3a3d3 https://git.kernel.org/stable/c/2a9d637c2a8fd8ac29ad9b29f28d122ef75c1a56 https://git.kernel.org/stable/c/4683ca76b3b7e5808338491c6eb3c20e6b4894d5