External risk intelligence

Linux kernel NFSD use-after-free vulnerability in client handling.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-90037

The vulnerability resides in the Linux kernel NFSD (NFS server) component. While NFS services can be exposed to a network, they are traditionally deployed within trusted internal networks or segmented environments rather than directly exposed to the public internet. Internet-facing NFS access is uncommon and generally considered a poor security practice.

Use After Free

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability in the Linux kernel's NFS server component could allow an attacker to exploit a use-after-free condition during client operations, potentially leading to system instability or compromise. The issue arises from how the system manages client data after a connection is closed, creating a window for exploitation.

  • Client data may be improperly handled.
  • Affects foundational operating system stability.
  • Confirm relevance and ensure system integrity.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by triggering a race condition within the Linux kernel's NFS server (NFSD) component. This race condition occurs during the cleanup of client data structures, specifically when a client is being forcefully expired while also undergoing normal timed-out entry reaping. If successful, this could allow an attacker to cause the system to read from freed memory, potentially leading to a system crash or other unintended behavior.

  • Entry condition: Attacker triggers client expiration.
  • Trigger point: Race condition during client cleanup.
  • Resulting risk: System instability or crash.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in the Linux kernel's NFS server could allow an attacker to cause a use-after-free condition when processing client requests. This occurs during the cleanup of timed-out NFS entries, potentially leading to system instability or the execution of arbitrary code when supported by specific race conditions.

  • Kernel data integrity at risk.
  • Race condition could trigger memory corruption.
  • System instability or arbitrary code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the Linux kernel's NFSD component primarily impacts teams responsible for maintaining the kernel and NFS services. Initial actions should focus on inventorying NFS deployments, assessing business criticality and network exposure, and identifying the accountable system or application owners to coordinate remediation.

  • Identify NFS service owners.
  • Verify NFS service exposure.
  • Plan kernel maintenance updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Linux kernel NFSD component?

NFSD, or NFS Server Daemon, is a kernel-level service that allows a Linux machine to share files and directories with other computers over a network. It is the engine that powers the Network File System protocol, enabling users or client systems to mount remote storage as if it were a local drive. It is widely used in enterprise data centers for centralized storage and distributed computing environments.

How does CVE-2026-90037 cause a use-after-free error?

This vulnerability involves a memory management flaw known as a use-after-free. It occurs when the kernel prematurely frees memory used by an NFS client but later attempts to access that same memory location again. Because the memory is no longer valid, this operation can lead to system instability, crashes, or unpredictable behavior.

Do I need to trigger a specific action to cause this bug?

Yes, this requires a precise race condition to occur. The vulnerability is triggered during the cleanup process for NFS client connections. Specifically, it happens when the system attempts to reap timed-out entries while simultaneously forcing a client to expire. Simply connecting to or using a normal NFS share is unlikely to trigger this; it requires overlapping teardown operations.

Is my system at risk according to Halo Surface Signal?

Halo Surface Signal identifies this as 'Unlikely' for many environments. While the NFS service can be reached over a network, it is traditionally restricted to internal, trusted, or segmented networks. Directly exposing NFS to the public internet is rare and considered a poor security practice, which significantly reduces the likelihood of external exploitation for most deployments.

What is the first step to address CVE-2026-90037?

Begin by auditing your infrastructure to identify which servers or systems are running the NFS service. Once you have a clear inventory, assess the network exposure of these specific NFS endpoints. If they are reachable, prioritize them for upcoming kernel maintenance and coordinate with system owners to plan for the necessary updates that resolve this memory management flaw.

References