Use-after-free in Linux kernel - CVE-2026-89663
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in the NFS server copy-notify stateid revocation logic when revoking copy-notify stateids while concurrent holders retain references. A remote attacker can trigger concurrent copy-notify stateid revocation to cause a denial of service.
The issue involves parent-stateid draining, OFFLOAD_CANCEL handling, and laundromat expiry.