CVE-2026-89682High· 7.0▾ TwilightA flaw was found in the Linux kernel's NFS daemon (nfsd) component. The nfsd_file_dispose_list_delayed() function, responsible for deferring file disposal, uses a separately allocated structure for its freeme queue. During network namespac…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 38.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
— → 6.6
none → medium
0.2% → 0.4%
— → 8.1
none → high
Last analysed / modified upstream
8.1 → 6.6
high → medium
6.6 → 8.1
medium → high
8.1 → 7
A flaw was found in the Linux kernel's NFS daemon (nfsd) component. The nfsd_file_dispose_list_delayed() function, responsible for deferring file disposal, uses a separately allocated structure for its freeme queue. During network namespace teardown, this structure can be prematurely freed. This allows other kernel callbacks to attempt to dereference the freed memory, leading to a use-after-free (UAF) vulnerability. A local attacker could potentially exploit this to cause a system crash or escalate privileges.
kernel: nfsd: fix fcache_disposal UAF by inlining dispose state into nfsd_net — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-14.
Affected:
No fix planned:
Not affected:
Affected
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-80947High· 7.0kernel: wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop (CVE-2026-80947)
CVE-2026-80981High· 7.0kernel: net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link() (CVE-2026-80981)
CVE-2026-89441Medium· 5.5kernel: mmc: via-sdmmc: cancel card-detect work on remove (CVE-2026-89441)
CVE-2026-89445High· 7.0kernel: iommufd: Fix UAF in selftest IOPF reporting (CVE-2026-89445)
CVE-2026-89675High· 7.0kernel: nfsd: fix UAF in async copy cancel and shutdown (CVE-2026-89675)
CVE-2026-89690High· 7.0kernel: nfsd: defer vfree of compound ops to fix rpc_status UAF (CVE-2026-89690)