CVE-2026-89659
A critical bug in the Linux kernel’s NFS server could let a client use a freed memory pointer during delegation revocation, potentially allowing an attacker to crash the system or execute arbitrary code. The issue has been fixed in the kernel, so updating to a patched version resolves the risk.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel NFS server (NFSD) – any system running the Linux kernel that uses NFSv4 delegations, typically Linux system administrators and users running NFS services.
Real-world impact
An attacker could trigger a use‑after‑free that may crash the NFS server or allow arbitrary code execution, potentially compromising the host.
Why this severity
The CVSS score of 9.8 reflects that the flaw is exploitable over the network with no authentication, and can lead to complete compromise of confidentiality, integrity, and availability.
What to do about it
- 01Upgrade your Linux kernel to a version that includes the fix for CVE-2026-89659.
- 02Restart your system to load the updated kernel.
NVD description indicates the vulnerability has been resolved.
Timeline
- Sep 11, 2026 · 2d agoPublishedDisclosed and added to the National Vulnerability Database.
- Sep 13, 2026 · 7h agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.