CVE-2026-89708
In the Linux kernel, the following vulnerability has been resolved:
nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown
After a DESTROY_SESSION the per-session teardown path can free a session while rpciod still holds an inflight callback rpc_task that dereferences clp->cl_cb_session. nfsd4_probe_callback_sync() flushes cl_callback_wq, but once nfsd4_run_cb_work() has called rpc_call_async() the rpc_task lives on rpciod; flushing the workqueue does not wait for it. rpc_shutdown_client() does drain rpciod tasks, but uses a 1-second wait_event_timeout — tasks stuck in rpc_delay() (e.g. 2-second NFS4ERR_DELAY retries) can outlive the drain.
Leer descripción completaMostrar menos
A second window exists in nfsd4_process_cb_update(). When __nfsd4_find_backchannel() returns NULL because unhash_session() has already removed the destroyed session from cl_sessions, setup_callback_client() takes the v4.1 early return so clp->cl_cb_session = ses never fires and the field retains a pointer to the about-to-be-freed session.
Fix both by converting cl_cb_session to an RCU-protected pointer:
Detalles técnicos trazas, registros y código del informe original
destroy path rpciod
------------ ------
unhash_session(ses)
nfsd4_probe_callback_sync(clp)
flush_workqueue(cl_callback_wq)
/* returns; rpc_task still live */
nfsd4_put_session_locked(ses)
free_session(ses) -> kfree(ses)
nfsd4_cb_sequence_done()
reads cb_clp->cl_cb_session
/* freed slab */
- Move the cl_cb_session = ses assignment in setup_callback_client()
to after rpc_create() succeeds, so it is only published when a
working backchannel exists. Clear cl_cb_session on the error
return in nfsd4_process_cb_update(). Both stores use
rcu_assign_pointer().
- Annotate cl_cb_session with __rcu. All rpciod-side readers use
rcu_read_lock()/rcu_dereference() and check for NULL, bailing to
the appropriate error or requeue path:
encode_cb_sequence4args(), decode_cb_sequence4resok(),
nfsd41_cb_get_slot(), nfsd41_cb_release_slot(),
nfsd4_cb_prepare(), and nfsd4_cb_sequence_done().
- Switch __free_session() from kfree() to kfree_rcu() so the
session slab is not reclaimed until after an RCU grace period,
guaranteeing that rpciod readers inside rcu_read_lock() never
dereference freed memory.
- Pass the session pointer to the nfsd_cb_seq_status and
nfsd_cb_free_slot tracepoints instead of having them re-read
cl_cb_session.
- nfsd4_cb_prepare() calls rpc_exit() when the session is NULL,
routing through the done/release path to requeue the callback.CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.44%
- Percentil entre todas las CVEs puntuadas: 36
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access85 % - Impacto principal
T1499.004Application or System Exploitationimpact75 % - Impacto secundario
T1565.001Stored Data Manipulationimpact65 %
Vulnerabilidad RCU use-after-free en nfsd del kernel Linux (AV:N, AC:L, PR:N) explotable remotamente. Impactos: negación de servicio por crash de rpciod y corrupción de sesiones NFS4.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-89708",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "dcbeaa68dbbdacbbb330a86c7fc95a28473fc209",
"lessThan": "2775ec1d617e665eab71ce0f13ab1f7959713a2b",
"versionType": "git"
},
{
"status": "affected",
"version": "dcbeaa68dbbdacbbb330a86c7fc95a28473fc209",
"lessThan": "f164eb52b6f3cbf40f07fe379f9f421f88e02f76",
"versionType": "git"
},
{
"status": "affected",
"version": "dcbeaa68dbbdacbbb330a86c7fc95a28473fc209",
"lessThan": "13bdd486c3aad4fc19e6d8b9c3556a4b4c190b25",
"versionType": "git"
},
{
"status": "affected",
"version": "dcbeaa68dbbdacbbb330a86c7fc95a28473fc209",
"lessThan": "01c5d5f58a5db9b0ee5afba2e49d3157788687b2",
"versionType": "git"
}
],
"programFiles": [
"fs/nfsd/nfs4callback.c",
"fs/nfsd/nfs4state.c",
"fs/nfsd/state.h",
"fs/nfsd/trace.h"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.38"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "2.6.38",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.50",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.4",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"fs/nfsd/nfs4callback.c",
"fs/nfsd/nfs4state.c",
"fs/nfsd/state.h",
"fs/nfsd/trace.h"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-11T20:19:58.140",
"references": [
{
"url": "https://git.kernel.org/stable/c/01c5d5f58a5db9b0ee5afba2e49d3157788687b2",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/13bdd486c3aad4fc19e6d8b9c3556a4b4c190b25",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2775ec1d617e665eab71ce0f13ab1f7959713a2b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f164eb52b6f3cbf40f07fe379f9f421f88e02f76",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown\n\nAfter a DESTROY_SESSION the per-session teardown path can free a\nsession while rpciod still holds an inflight callback rpc_task that\ndereferences clp->cl_cb_session. nfsd4_probe_callback_sync() flushes\ncl_callback_wq, but once nfsd4_run_cb_work() has called\nrpc_call_async() the rpc_task lives on rpciod; flushing the workqueue\ndoes not wait for it. rpc_shutdown_client() does drain rpciod tasks,\nbut uses a 1-second wait_event_timeout — tasks stuck in rpc_delay()\n(e.g. 2-second NFS4ERR_DELAY retries) can outlive the drain.\n\n destroy path rpciod\n ------------ ------\n unhash_session(ses)\n nfsd4_probe_callback_sync(clp)\n flush_workqueue(cl_callback_wq)\n /* returns; rpc_task still live */\n nfsd4_put_session_locked(ses)\n free_session(ses) -> kfree(ses)\n nfsd4_cb_sequence_done()\n reads cb_clp->cl_cb_session\n /* freed slab */\n\nA second window exists in nfsd4_process_cb_update(). When\n__nfsd4_find_backchannel() returns NULL because unhash_session() has\nalready removed the destroyed session from cl_sessions,\nsetup_callback_client() takes the v4.1 early return so\nclp->cl_cb_session = ses never fires and the field retains a pointer\nto the about-to-be-freed session.\n\nFix both by converting cl_cb_session to an RCU-protected pointer:\n\n - Move the cl_cb_session = ses assignment in setup_callback_client()\n to after rpc_create() succeeds, so it is only published when a\n working backchannel exists. Clear cl_cb_session on the error\n return in nfsd4_process_cb_update(). Both stores use\n rcu_assign_pointer().\n\n - Annotate cl_cb_session with __rcu. All rpciod-side readers use\n rcu_read_lock()/rcu_dereference() and check for NULL, bailing to\n the appropriate error or requeue path:\n encode_cb_sequence4args(), decode_cb_sequence4resok(),\n nfsd41_cb_get_slot(), nfsd41_cb_release_slot(),\n nfsd4_cb_prepare(), and nfsd4_cb_sequence_done().\n\n - Switch __free_session() from kfree() to kfree_rcu() so the\n session slab is not reclaimed until after an RCU grace period,\n guaranteeing that rpciod readers inside rcu_read_lock() never\n dereference freed memory.\n\n - Pass the session pointer to the nfsd_cb_seq_status and\n nfsd_cb_free_slot tracepoints instead of having them re-read\n cl_cb_session.\n\n - nfsd4_cb_prepare() calls rpc_exit() when the session is NULL,\n routing through the done/release path to requeue the callback."
}
],
"lastModified": "2026-09-21T14:17:25.690",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}