---
id: CVE-2026-90039
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  NFSD: Guard admin state-revocation walks with NFSD_NET_UP

  Writing to /proc/fs/nfsd/unlock_filesystem, or sending the
  NFSD_CMD_UNLOCK_FILESYSTEM or NFSD_CMD_UNLOCK_EXPO…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  NFSD: Guard admin state-revocation walks with NFSD_NET_UP

  Writing to /proc/fs/nfsd/unlock_filesystem, or sending the
  NFSD_CMD_UNLOCK_FILESYSTEM or NFSD_CMD_UNLOCK_EXPO…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 1ac3629bf012592cb0320e52a1cceb319a05ad17 <
    104a51265042b4424085741c963cb858ac29ec0b
  - >-
    Linux >= 1ac3629bf012592cb0320e52a1cceb319a05ad17 <
    0146467a2fce845cb6629979c3e9c58dd3d3a6a3
  - >-
    Linux >= 1ac3629bf012592cb0320e52a1cceb319a05ad17 <
    2f3e6638aebc0ab8afb8b4e9816ea9a1cad85378
  - Linux 6.9
published: '2026-09-16'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T14:17:28.123'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90039'
references:
  - url: 'https://git.kernel.org/stable/c/0146467a2fce845cb6629979c3e9c58dd3d3a6a3'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/104a51265042b4424085741c963cb858ac29ec0b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/2f3e6638aebc0ab8afb8b4e9816ea9a1cad85378'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/73bf459d696ecf207a9037bf9bb70c51a459469e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
epss: 0.00209
epssPercentile: 0.0981
ingestedAt: '2026-09-16T10:53:53.930Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

NFSD: Guard admin state-revocation walks with NFSD_NET_UP

Writing to /proc/fs/nfsd/unlock_filesystem, or sending the
NFSD_CMD_UNLOCK_FILESYSTEM or NFSD_CMD_UNLOCK_EXPORT netlink command,
walks the NFSv4 client hash tables to revoke open state and cancel
async COPY operations.  All three handlers gate that walk on
nn->nfsd_serv, but a listener added via portlist or netlink
listener_set sets nn->nfsd_serv before any nfsd thread starts.
nfsd_startup_net() has not yet allocated nn->conf_id_hashtbl, so the
walkers dereference a NULL table.  A local administrator with
CAP_SYS_ADMIN can crash the kernel this way without ever starting the
server.

nn->nfsd_serv is set when the service is created, which precedes
table allocation.  NFSD_NET_UP instead brackets the window where the
tables are live: set at the end of nfsd_startup_net() and cleared in
nfsd_shutdown_net() after they are freed, both under nfsd_mutex.
Gating the three unlock paths on NFSD_NET_UP fixes the startup-time
NULL dereference while preserving the earlier post-shutdown
use-after-free fix.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
