Use-after-free in Linux kernel - CVE-2026-89712
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a use-after-free in nfsd4_ssc_expire_umount() when processing concurrent NFS server operations while an expired inter-server source mount is being unmounted. A remote attacker can trigger concurrent operations that cause the expiration walk to dereference a freed nfsd4_ssc_umount_item to cause a denial of service.