Use-after-free in Linux kernel - CVE-2026-89677
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in the nfsd4_create_file() function when handling file creation on an NFS-exported filesystem. A remote attacker can cause an NFS server to return a filehandle that matches a directory already in the dcache to cause a denial of service.