« Volver al listado

CVE-2026-90234

Estado: RecibidaAlta (7.5)—

In the Linux kernel, the following vulnerability has been resolved:

NFS: Return a delegation the client fails to record

When an NFS server grants a delegation in an OPEN reply, nfs_inode_set_delegation() records it on the client. However, three of its error flows return without sending DELEGRETURN.

A delegation can be relinquished only by DELEGRETURN (RFC 8881 Section 20.2.4), so dropping one silently leaves the server believing the client still holds it. If the server happens to recall that delegation, the client answers CB_RECALL with NFS4ERR_BADHANDLE because it has no record of the stateid.

Leer descripción completaMostrar menos

The server revokes the delegation and moves it onto its cl_revoked list, because the client never sends the FREE_STATEID that would drain it. Every subsequent SEQUENCE reply then carries SEQ4_STATUS_RECALLABLE_STATE_REVOKED, and the client's state manager loops issuing TEST_STATEID across its delegations without ever clearing the condition.

The window is easy to reach now that a server offers a write delegation on any write OPEN: a delegation recalled for one opener races a re-open that the server answers with a fresh write delegation.

Instead of dropping it, hand the delegation back during these error flows.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad en kernel Linux accesible por red sin privilegios que causa DoS al dejar delegaciones huérfanas; ataque remoto con AV:N/PR:N genera bucles en gestor de estado.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90234",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "ade04647dd56881e285983af3db702d56ee97e86",
              "lessThan": "92533e49fe3c455088657b862cf3562260c0ce25",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ade04647dd56881e285983af3db702d56ee97e86",
              "lessThan": "220af23d863995091f0edeb1e6aa0945b3db8b37",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/nfs/delegation.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/nfs/delegation.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:19.293",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/220af23d863995091f0edeb1e6aa0945b3db8b37",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/92533e49fe3c455088657b862cf3562260c0ce25",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFS: Return a delegation the client fails to record\n\nWhen an NFS server grants a delegation in an OPEN reply,\nnfs_inode_set_delegation() records it on the client. However, three\nof its error flows return without sending DELEGRETURN.\n\nA delegation can be relinquished only by DELEGRETURN (RFC 8881\nSection 20.2.4), so dropping one silently leaves the server believing\nthe client still holds it. If the server happens to recall that\ndelegation, the client answers CB_RECALL with NFS4ERR_BADHANDLE\nbecause it has no record of the stateid. The server revokes the\ndelegation and moves it onto its cl_revoked list, because the client\nnever sends the FREE_STATEID that would drain it. Every subsequent\nSEQUENCE reply then carries SEQ4_STATUS_RECALLABLE_STATE_REVOKED,\nand the client's state manager loops issuing TEST_STATEID across its\ndelegations without ever clearing the condition.\n\nThe window is easy to reach now that a server offers a write\ndelegation on any write OPEN: a delegation recalled for one opener\nraces a re-open that the server answers with a fresh write\ndelegation.\n\nInstead of dropping it, hand the delegation back during these error\nflows."
    }
  ],
  "lastModified": "2026-09-18T18:17:48.277",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}