{"id":"CVE-2026-90036","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: Prevent client use-after-free during blocked-lock reaping\n\nA bare lock owner -- its only remaining reference a blocked lock on\nnn->blocked_locks_lru -- holds a ra…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: Prevent client use-after-free during blocked-lock reaping\n\nA bare lock owner -- its only remaining reference a blocked lock on\nnn->blocked_locks_lru -- holds a ra…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","vendor":"Linux","product":"Linux","affected":["Linux >= 7919d0a27f1e7cb324e023776aa1cbff00f1ee7b < cd489b03587378645fe0d20142a33f1ed60bac98","Linux >= 7919d0a27f1e7cb324e023776aa1cbff00f1ee7b < 6fedb2eaff77554ca7a0deffd2e8bc0d6e8b38b0","Linux >= 7919d0a27f1e7cb324e023776aa1cbff00f1ee7b < 9026932ac8be4d0ae01db47f23619a98cc57b671","Linux 4.9"],"published":"2026-09-16","updated":"2026-09-21","sourceUpdated":"2026-09-21T14:17:27.843","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90036","references":[{"url":"https://git.kernel.org/stable/c/6fedb2eaff77554ca7a0deffd2e8bc0d6e8b38b0","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7081224a59a0ca4edcd62c068588f4d900199a18","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9026932ac8be4d0ae01db47f23619a98cc57b671","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cd489b03587378645fe0d20142a33f1ed60bac98","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"epss":0.00652,"epssPercentile":0.49031,"ingestedAt":"2026-09-16T10:53:53.934Z","slug":"CVE-2026-90036","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: Prevent client use-after-free during blocked-lock reaping\n\nA bare lock owner -- its only remaining reference a blocked lock on\nnn->blocked_locks_lru -- holds a raw pointer to its nfs4_client but\nno reference keeping the client alive. When the per-net laundromat\nreaps such a lock, freeing the nbl drops the owner reference\nheld through flc_owner, and the final nfs4_put_stateowner()\ntakes the client's cl_lock. Because the laundromat detaches the\nnbl first, __destroy_client() no longer finds it, so a concurrent\nforce_expire_client() can free the client before nfs4_put_stateowner()\nruns, dereferencing cl_lock in freed memory.\n\nPin the client with cl_rpc_users before dropping\nnn->blocked_locks_lock, and skip clients already expiring, whose\nblocked locks __destroy_client() frees while holding an owner\nreference. Take nn->client_lock outside nn->blocked_locks_lock.\nEvery other site holds nn->blocked_locks_lock as a leaf, acquiring\nno further lock, so placing nn->client_lock outside it cannot form\na lock-order cycle.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":205001,"id":"CVE-2026-90036","ts":1789570702626,"field":"cvss","old":null,"new":"9.8"},{"seq":205000,"id":"CVE-2026-90036","ts":1789570702626,"field":"severity","old":"none","new":"critical"}]}