CVE-2026-89662
A critical bug in the Linux kernel’s NFS daemon could let an attacker crash the server by freeing a lock owner that is still in use, causing a NULL dereference during client teardown.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel NFS daemon (nfsd) – any system running the NFS server component of the Linux kernel, such as servers hosting NFS shares.
Real-world impact
An attacker could crash the NFS server, leading to a denial‑of‑service and potentially enabling further exploitation if the crash allows privilege escalation or code execution.
Why this severity
The CVSS score of 9.8 reflects the high impact on confidentiality, integrity, and availability, and the fact that the flaw can be triggered remotely with no authentication or user interaction.
What to do about it
- 01Update the Linux kernel to a version that includes the fix for CVE-2026-89662.
NVD description indicates the vulnerability has been resolved in the Linux kernel.
Timeline
- Sep 11, 2026 · 2d agoPublishedDisclosed and added to the National Vulnerability Database.
- Sep 13, 2026 · 7h agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.