« Volver al listado

CVE-2026-90236

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

NFSD: Release the export reference when reaping open stateids

nfs4_put_stid() releases the svc_export tracked in nfs4_stid.sc_export, but free_ol_stateid_reaplist() frees open and lock stateids by calling ->sc_free() directly, bypassing that path. An open stateid takes an sc_export reference in nfs4_open() and a lock stateid takes its own in init_lock_stateid(); both reach free_ol_stateid_reaplist() through their normal teardown, the open stateid via release_open_stateid() and the lock stateid via nfsd4_release_lockowner(), each through put_ol_stateid_locked(). The reference is therefore never dropped, pinning the export and blocking unmount for the lifetime of the stateid.

Leer descripción completaMostrar menos

Release sc_export in free_ol_stateid_reaplist() the way nfs4_put_stid() does. ->sc_free() runs once per stateid, and a stateid reaches free_ol_stateid_reaplist() or nfs4_put_stid() but never both, so the reference is dropped exactly once. Revoked stateids reach this path with sc_export already cleared by drop_stid_export(), so they are skipped rather than double-freed.

nfs4_put_stid() itself read sc_export before acquiring cl_lock. drop_stid_export() clears that field and releases the reference under cl_lock, so a concurrent revocation could drop the export in the window between the read and the final put, releasing the same reference twice. Read sc_export while cl_lock is held so the two paths serialize and the reference is released exactly once.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90236",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "ba0cde5dc81d214684b8ea0bd87414ba2f48fe02",
              "lessThan": "7458727fd7cb79d09e5120b6fecc1ad11cdb0946",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ba0cde5dc81d214684b8ea0bd87414ba2f48fe02",
              "lessThan": "6480bd703684ed3f760e9e36c4a699033c0806ae",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/nfsd/nfs4state.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.2"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.2",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/nfsd/nfs4state.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:19.533",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/6480bd703684ed3f760e9e36c4a699033c0806ae",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7458727fd7cb79d09e5120b6fecc1ad11cdb0946",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: Release the export reference when reaping open stateids\n\nnfs4_put_stid() releases the svc_export tracked in\nnfs4_stid.sc_export, but free_ol_stateid_reaplist() frees open and\nlock stateids by calling ->sc_free() directly, bypassing that path.\nAn open stateid takes an sc_export reference in nfs4_open() and a\nlock stateid takes its own in init_lock_stateid(); both reach\nfree_ol_stateid_reaplist() through their normal teardown, the open\nstateid via release_open_stateid() and the lock stateid via\nnfsd4_release_lockowner(), each through put_ol_stateid_locked().\nThe reference is therefore never dropped, pinning the export and\nblocking unmount for the lifetime of the stateid.\n\nRelease sc_export in free_ol_stateid_reaplist() the way\nnfs4_put_stid() does. ->sc_free() runs once per stateid, and a\nstateid reaches free_ol_stateid_reaplist() or nfs4_put_stid() but\nnever both, so the reference is dropped exactly once. Revoked\nstateids reach this path with sc_export already cleared by\ndrop_stid_export(), so they are skipped rather than double-freed.\n\nnfs4_put_stid() itself read sc_export before acquiring cl_lock.\ndrop_stid_export() clears that field and releases the reference\nunder cl_lock, so a concurrent revocation could drop the export in\nthe window between the read and the final put, releasing the same\nreference twice. Read sc_export while cl_lock is held so the two\npaths serialize and the reference is released exactly once."
    }
  ],
  "lastModified": "2026-09-17T17:17:19.533",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}