Improper resource shutdown or release in Linux kernel - CVE-2026-90234
Published: September 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource shutdown or release in nfs_inode_set_delegation() when handling NFS delegation grants during error flows. A remote attacker can trigger a delegation recall that races with a re-open operation to cause a denial of service.