CVE-2026-89712

Source
https://cve.org/CVERecord?id=CVE-2026-89712
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89712.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89712
Downstream
Related
Published
2026-09-11T19:46:27Z
Modified
2026-09-25T18:27:15Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock
Details

In the Linux kernel, the following vulnerability has been resolved:

NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock

nfsd4_ssc_expire_umount() walks nn->nfsd_ssc_mount_list with list_for_each_entry_safe(ni, tmp, ...). For each expired entry it sets nsui_busy = true, drops nfsd_ssc_lock to run mntput() on the source vfsmount, then reacquires the lock to list_del + kfree the entry and continue iterating via the macro's saved tmp pointer.

The nsui_busy flag protects the current ni from concurrent nfsd4_ssc_setup_dul() finders during the lock-drop window, but it does not pin tmp. Another nfsd RPC thread that fails its source- server mount and reaches nfsd4_ssc_cancel_dul() will, during that same window, take nfsd_ssc_lock, list_del + kfree its own ssc_umount item, and release the lock. If that item is the saved tmp of the expire walk, the next iteration dereferences a freed nfsd4_ssc_umount_item.

Restart the walk from the head after the mntput() unlock window so no saved next pointer survives the lock-drop. The list is bounded by the number of active inter-server source mounts (typically small) and the expire delayed-work runs periodically rather than per-IO, so the restart is cheap.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89712.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
a4bc287943f5695209ff36bdc89f17b48d68fae7
Fixed
2b59029b8f24a99b5d844af2da3950d39d36eeea
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f4e44b393389c77958f7c58bf4415032b4cda15b
Fixed
d9e151fea5ed706c1284adacabd869b0be745db2
Fixed
659ee3da073164e1e6e40dfcbc26eeed85845f93
Fixed
60680ae7243b22de3d09be990d8e23bcfc4af837
Fixed
77de363d9a1c8cd35f20482782c612cda085791a
Fixed
4ed8d2317aef21cc2a9e5a55d6b59860b4b151a8
Fixed
7377fa964b8aaf47cb04e5efcc4c82d15e8c2ce9
Fixed
036c1b182f4da65363e79ec0ac276edc6b7296e5
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5.10.220
Fixed
5.10.270

Affected versions

v5.*
v5.10.220
v5.10.221
v5.10.222
v5.10.223
v5.10.224
v5.10.225
v5.10.226
v5.10.227
v5.10.228
v5.10.229
v5.10.230
v5.10.231
v5.10.232
v5.10.233
v5.10.234
v5.10.235
v5.10.236
v5.10.237
v5.10.238
v5.10.239
v5.10.240
v5.10.241
v5.10.242
v5.10.243
v5.10.244
v5.10.245
v5.10.246
v5.10.247
v5.10.248
v5.10.249
v5.10.250
v5.10.251
v5.10.252
v5.10.253
v5.10.254
v5.10.255
v5.10.256
v5.10.257
v5.10.258
v5.10.259
v5.10.260
v5.10.261
v5.10.262
v5.10.263
v5.10.264
v5.10.265
v5.10.266
v5.10.267
v5.10.268
v5.10.269

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89712.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.14.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.12.109
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.18.50
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
7.2.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89712.json"