Use-after-free in Linux kernel - CVE-2026-89545
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to trigger a use-after-free.
The vulnerability exists due to improper RCU synchronization in the SunRPC service request cleanup routine when RCU readers traverse the thread list after a service request is removed. A local user can cause RCU readers to dereference freed request argument memory to trigger a use-after-free.
The issue affects request data accessed by readers such as nfsd_nl_rpc_status_get_dumpit().