CVE-2026-90148

Source
https://cve.org/CVERecord?id=CVE-2026-90148
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90148.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90148
Downstream
Published
2026-09-17T16:06:42Z
Modified
2026-09-18T03:48:35Z
Summary
NFSv4: Fix incorrect argument passed to nfs4_delete_lease() in nfs4_add_lease()
Details

In the Linux kernel, the following vulnerability has been resolved:

NFSv4: Fix incorrect argument passed to nfs4_delete_lease() in nfs4_add_lease()

When nfs4_add_lease() races with a delegation return, it calls nfs4_delete_lease() to clean up. Previously, it passed priv, which can legitimately be NULL. Passing a NULL priv eventually leads to a NULL pointer dereference in generic_setlease().

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90148.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
e93a5e9306a576011f03011b492d4fbaa274477b
Fixed
ff7244faa13b23e9acfad9df0438f0b44b338f62
Fixed
d148a652d52fd6aee96daf798922eb800ebb3018
Fixed
d179ff22cd8514f966966fd9ad425dcbb98e1ada
Fixed
468e458ffde907ba19acd2102ca1fbb8f6fbede2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90148.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.14.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90148.json"