External risk intelligence

Linux Kernel NFSD Client Use-After-Free Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-89659

The vulnerability exists within the Linux kernel's NFSD (NFS server) component. While NFS can be exposed to the network, it is typically deployed within internal, trusted environments or behind firewalls to manage file sharing and is not intended for direct exposure to the public internet.

Use After Free

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in the Linux kernel's network file system service could potentially allow for system instability or crashes. This issue involves how client connections are managed during a process called delegation revocation.

  • A technical flaw in the Linux kernel was fixed.
  • This impacts file-sharing services.
  • Confirm if your Linux systems are affected.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by triggering a specific sequence of events related to NFS delegation revocation. This occurs when a client's delegated file access is recalled, and the system is in the process of cleaning up resources. The vulnerability arises from a race condition where the client's resources might be freed prematurely while still being referenced, potentially leading to a use-after-free error.

  • Network access required.
  • Triggered by delegation recall timing.
  • Leads to client resource corruption.

Live Threat

Current exploitation, exposure, and threat context

When supported, this vulnerability could allow an attacker to cause a crash or execute arbitrary code within the Linux kernel's NFS server by exploiting a use-after-free condition during delegation revocation. This could affect the availability and integrity of the NFS service and potentially lead to unauthorized access or control of the server.

  • NFS server processes and data.
  • Through a network-based attack on NFS.
  • Server instability and potential compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in the Linux kernel's NFSD component requires immediate attention from infrastructure and platform teams responsible for NFS services. The first practical step is to identify all NFS servers, confirm their exposure and business criticality, and then coordinate with accountable owners for remediation, potentially involving vendor coordination if using a managed service.

  • Infrastructure and platform teams own this.
  • Verify NFS server exposure and criticality.
  • Plan for safe, coordinated remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Linux kernel NFSD component?

NFSD, or NFS Server Daemon, is the part of the Linux kernel that enables a machine to act as a file server. It allows other computers on a network to mount and access files as if they were stored locally. It is a fundamental service for distributed file sharing in enterprise environments, data centers, and storage clusters.

What does this use-after-free vulnerability mean?

A use-after-free occurs when software continues to use a pointer to a memory location after the system has already freed or reclaimed that memory. In this case, the kernel improperly manages the lifecycle of a client connection during a specific cleanup process, leading to a race condition where the kernel attempts to access data that no longer exists.

How is this vulnerability triggered?

The flaw is triggered during the revocation of an NFS delegation, which is a mechanism where the server temporarily grants a client permission to manage file access locally. If a delegation is recalled and expires at a specific moment, the system may mistakenly free client resources while still referencing them. Simply performing standard NFS operations will not trigger this; it requires specific, precise timing during the server's resource cleanup.

Is my server at risk if it is not on the internet?

Halo Surface Signal notes that while this issue is theoretically reachable via the network, NFS is typically designed for trusted internal environments and is rarely intended for direct public internet exposure. If your NFS server is isolated behind firewalls or restricted to a private, trusted network, the likelihood of an external attacker reaching the vulnerable service is significantly lower.

What should I do to address CVE-2026-89659?

Start by identifying all systems in your environment that run the NFS server service. Prioritize these based on their business criticality and current network placement. Since this is a flaw within the Linux kernel, the primary response involves monitoring your Linux distribution's security updates for a patched kernel version. Coordinate with your platform teams to plan for the application of these updates through standard maintenance cycles.

References