« Volver al listado

CVE-2026-90039

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

NFSD: Guard admin state-revocation walks with NFSD_NET_UP

Writing to /proc/fs/nfsd/unlock_filesystem, or sending the NFSD_CMD_UNLOCK_FILESYSTEM or NFSD_CMD_UNLOCK_EXPORT netlink command, walks the NFSv4 client hash tables to revoke open state and cancel async COPY operations. All three handlers gate that walk on nn->nfsd_serv, but a listener added via portlist or netlink listener_set sets nn->nfsd_serv before any nfsd thread starts. nfsd_startup_net() has not yet allocated nn->conf_id_hashtbl, so the walkers dereference a NULL table. A local administrator with CAP_SYS_ADMIN can crash the kernel this way without ever starting the server.

Leer descripción completaMostrar menos

nn->nfsd_serv is set when the service is created, which precedes table allocation. NFSD_NET_UP instead brackets the window where the tables are live: set at the end of nfsd_startup_net() and cleared in nfsd_shutdown_net() after they are freed, both under nfsd_mutex. Gating the three unlock paths on NFSD_NET_UP fixes the startup-time NULL dereference while preserving the earlier post-shutdown use-after-free fix.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90039",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "1ac3629bf012592cb0320e52a1cceb319a05ad17",
              "lessThan": "73bf459d696ecf207a9037bf9bb70c51a459469e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1ac3629bf012592cb0320e52a1cceb319a05ad17",
              "lessThan": "104a51265042b4424085741c963cb858ac29ec0b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1ac3629bf012592cb0320e52a1cceb319a05ad17",
              "lessThan": "0146467a2fce845cb6629979c3e9c58dd3d3a6a3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1ac3629bf012592cb0320e52a1cceb319a05ad17",
              "lessThan": "2f3e6638aebc0ab8afb8b4e9816ea9a1cad85378",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/nfsd/nfs4proc.c",
            "fs/nfsd/nfs4state.c",
            "fs/nfsd/nfsctl.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.9"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.9",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.51",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/nfsd/nfs4proc.c",
            "fs/nfsd/nfs4state.c",
            "fs/nfsd/nfsctl.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-16T11:17:17.110",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0146467a2fce845cb6629979c3e9c58dd3d3a6a3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/104a51265042b4424085741c963cb858ac29ec0b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2f3e6638aebc0ab8afb8b4e9816ea9a1cad85378",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/73bf459d696ecf207a9037bf9bb70c51a459469e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: Guard admin state-revocation walks with NFSD_NET_UP\n\nWriting to /proc/fs/nfsd/unlock_filesystem, or sending the\nNFSD_CMD_UNLOCK_FILESYSTEM or NFSD_CMD_UNLOCK_EXPORT netlink command,\nwalks the NFSv4 client hash tables to revoke open state and cancel\nasync COPY operations.  All three handlers gate that walk on\nnn->nfsd_serv, but a listener added via portlist or netlink\nlistener_set sets nn->nfsd_serv before any nfsd thread starts.\nnfsd_startup_net() has not yet allocated nn->conf_id_hashtbl, so the\nwalkers dereference a NULL table.  A local administrator with\nCAP_SYS_ADMIN can crash the kernel this way without ever starting the\nserver.\n\nnn->nfsd_serv is set when the service is created, which precedes\ntable allocation.  NFSD_NET_UP instead brackets the window where the\ntables are live: set at the end of nfsd_startup_net() and cleared in\nnfsd_shutdown_net() after they are freed, both under nfsd_mutex.\nGating the three unlock paths on NFSD_NET_UP fixes the startup-time\nNULL dereference while preserving the earlier post-shutdown\nuse-after-free fix."
    }
  ],
  "lastModified": "2026-09-21T14:17:28.123",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}