# CVE-2026-89662

## Summary

- **CVE ID:** CVE-2026-89662
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 14, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

NFSD: Prevent lock owner use-after-free during client teardown

__destroy_client() releases a client's open owners, but a lock owner
whose only reference is a blocked lock (nbl) stays on
cl_ownerstr_hashtbl.  client_has_state() does not count a bare owner,
so DESTROY_CLIENTID can reach __destroy_client() with such owners
present.

__destroy_client() then walks the table, calling remove_blocked_locks()
on each owner without a reference.  Freeing a blocked lock drops the
owner reference held via flc_owner.  The per-net laundromat reaps
blocked locks from nn->blocked_locks_lru independently of client state.
The two paths share blocked_locks_lock only for the list splice, not
the owner's lifetime.  The laundromat therefore frees the owner as
__destroy_client() dereferences it, a NULL dereference in
remove_blocked_locks().

nfsd4_release_lockowner() holds a reference across the same call;
__destroy_client() does not.  Hold cl_lock across the walk, taking a
reference and unhashing each owner, then drop it before
remove_blocked_locks() and nfs4_put_stateowner(), which take
blocked_locks_lock and cl_lock.

## Affected Products

- Linux — Linux (68ef3bc3166468678d5e1fdd216628c35bd1186f)
- Linux — Linux (e294c4c2d33b7307a89cdf31bec08a112d6a9297)
- Linux — Linux (797bfd05d4040fbf766198b3cfcc1838002cc890)
- Linux — Linux (0f44e9da465ea259b6c9f31a627f3c50a16e1679)
- Linux — Linux (4.9.91)
- Linux — Linux (4.14.31)
- Linux — Linux (4.15.14)
- Linux — Linux (4.16)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)
- Linux — Linux (5.10.270)
- Linux — Linux (5.15.221)
- Linux — Linux (6.1.188)
- Linux — Linux (6.6.157)

## References

- [CNA](https://git.kernel.org/stable/c/a6ead6fff3a7d03e49845f048f7000a2e0d34431)
- [CNA](https://git.kernel.org/stable/c/4804c58f73a80d12df1de323bf97a164f6ee8743)
- [CNA](https://git.kernel.org/stable/c/8cf4ff0a7c083dd5e0067f517d63979b74b66649)
- [CNA](https://git.kernel.org/stable/c/5e2fa29d223a9a1e6a948e40b109d09081d1decd)
- [CNA](https://git.kernel.org/stable/c/42d7954b0a1907d4ef122aef94561952a033cdc3)
- [CNA](https://git.kernel.org/stable/c/bb38ff8b4dafbbd1781ad37cd96722fdf2cd972a)
- [CNA](https://git.kernel.org/stable/c/b8bad5a11416b26cc7fd4b18fba46d75ff636558)
- [CNA](https://git.kernel.org/stable/c/1ce74d1b7770e69735e8f8e509807af4ff9c8ee7)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.68%
- **EPSS Percentile:** 50.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._