External risk intelligence

Linux Kernel NFSD Use-After-Free Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-90036

This vulnerability exists in the Linux kernel NFSD (NFS server) component. While NFS can be exposed to the internet, it is standard practice to restrict NFS traffic to internal, trusted networks or behind firewalls. Public internet exposure of NFS services is uncommon and generally considered a misconfiguration.

Use After Free

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability in the Linux kernel's NFS server could allow an attacker to gain control of affected systems. The issue arises from how the kernel manages client data when certain locks are released, potentially leading to system instability or unauthorized access. It is important to confirm if your organization utilizes this specific kernel component in a way that might be exposed to potential threats.

  • Kernel flaw allows unauthorized access and control.
  • Matters for systems using the NFS server component.
  • Confirm relevance and exposure to your environment.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by triggering a race condition within the Linux kernel's NFS server (NFSD) component. This condition arises when the system attempts to clean up client locks, potentially leading to a use-after-free error if a client is simultaneously being expired. Such an error could allow an attacker to compromise the kernel's integrity.

  • Network access required.
  • Triggered during client lock cleanup.
  • Leads to kernel compromise.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in the Linux kernel's NFSD could potentially impact the stability of the system. It involves a use-after-free condition during the handling of blocked locks, which could lead to crashes or unpredictable behavior when processing NFS client operations.

  • Kernel stability and service availability.
  • Client lock operations could trigger a crash.
  • System instability or denial of service.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the Linux kernel's NFSD component requires immediate attention from infrastructure and platform teams responsible for NFS services. The first practical step is to identify all instances of the affected Linux kernel, confirm if the NFS service is exposed externally or to untrusted networks, and then determine the business criticality of each instance to prioritize remediation.

  • Identify and assess NFS service exposure.
  • Confirm business criticality of affected systems.
  • Plan and coordinate remediation efforts.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Linux kernel NFSD component?

NFSD, or NFS server, is a core Linux kernel subsystem that enables a computer to share files and directories across a network. It allows remote clients to mount these exported file systems as if they were local storage, a process essential for data sharing and centralized storage in server environments.

What does use-after-free mean in CVE-2026-90036?

This is a memory management flaw where the system attempts to use a data structure after it has already been deleted or freed. In this specific vulnerability, the kernel incorrectly manages references to NFS client information during lock cleanup, potentially allowing memory to be accessed after it is marked as available for other tasks.

How is this race condition triggered?

The issue occurs when the kernel's background process for cleaning up old locks runs at the same time a client connection is being forcefully removed. If these events overlap, the system may try to access a data structure for a client that has already been destroyed. Standard NFS operations that do not involve this specific race condition during client expiration will not trigger the bug.

Is my system at risk according to Halo Surface Signal?

Halo Surface Signal identifies this risk as 'Unlikely' for most environments because NFS traffic is typically confined to trusted internal networks. While the vulnerability requires network access, exposing NFS directly to the public internet is considered a significant misconfiguration, meaning systems shielded by firewalls are much less likely to be reachable by potential attackers.

What should I do first to address this?

Start by identifying which of your Linux servers are actively running the NFS service. Once you have a list, evaluate their network placement to confirm they are not accessible from untrusted networks or the public internet. Prioritize updating the kernel on any systems that are exposed or handle highly critical business data.

References