External risk intelligence

Linux Kernel NFSv4 Callback IDR Entry Removal Failure Leads to Stale Pointer

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-90151

This vulnerability exists within the internal memory management and allocation paths of the Linux kernel's NFSv4 client implementation. It relates to low-level client-side resource teardown during failure scenarios, which does not constitute an internet-facing service or an externally reachable interface.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability involves an issue in the Linux kernel's NFSv4 client handling during setup failures, where a callback identifier might not be correctly removed. This could lead to a stale pointer being used, potentially impacting system stability or integrity if exploited. The primary concern is confirming whether this specific internal kernel behavior is relevant to our environment.

  • Kernel bug in client setup can leave bad pointers.
  • Matters if Linux NFSv4 clients are used.
  • Confirm relevance and exposure to internal systems.

Attack Path

How an attacker could exploit the issue

A vulnerability in the Linux kernel's NFSv4 client could allow an attacker to trigger a use-after-free condition. This occurs when the client fails during its setup, leading to an improperly freed resource. Subsequent operations that try to use this freed resource can cause a crash or other unintended behavior.

  • No special access required.
  • Callback ID lookup on freed client.
  • Potential for denial of service or code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could affect system data when the NFSv4 client initialization fails. Under these conditions, a stale pointer in the callback IDR could lead to a lookup finding freed memory, potentially impacting data integrity and system stability.

  • NFSv4 client data.
  • Stale pointer lookup on allocation failure.
  • System instability or data corruption.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the Linux kernel's NFSv4 implementation requires investigation by teams managing Linux infrastructure. The first step is to identify all systems running the affected kernel version, determine their exposure to NFSv4 callbacks, and assess business criticality. Once identified, the accountable owner for each system must be confirmed to plan appropriate remediation or mitigation.

  • Own the issue and impacted systems.
  • Verify NFSv4 callback exposure and criticality.
  • Plan and coordinate remediation activities.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Linux kernel NFSv4 client?

The NFSv4 client is a core component of the Linux kernel that allows a computer to access files and directories stored on remote servers over a network. It acts as the bridge between local applications and shared network storage, managing the complex communication protocols required to handle data requests and maintain connections to distributed file systems.

What does CVE-2026-90151 mean for system memory?

This vulnerability involves a memory management error known as a use-after-free. When the kernel fails to set up an NFSv4 client properly, it prematurely frees memory while still leaving a reference to it active. This creates a stale pointer, meaning the system might mistakenly try to access or use memory that has already been cleared, potentially causing crashes or unpredictable behavior.

How is this CVE-2026-90151 vulnerability triggered?

The condition occurs specifically when an NFSv4 client allocation fails during initialization. An attacker cannot trigger this simply by sending a standard network request; it relies on internal memory allocation errors. If the setup process is interrupted or fails, the kernel fails to clean up a specific callback identifier, leaving the system in a vulnerable state for future lookups.

Is my system at risk according to Halo Surface Signal?

Halo Surface Signal assesses the risk as very unlikely. This is because the bug exists in internal kernel memory management paths rather than an internet-facing network interface. Since the issue is tied to low-level client-side resource handling during specific failure scenarios, it is not directly reachable by external network traffic.

How should I respond to this Linux kernel issue?

Start by identifying all Linux systems in your environment that utilize NFSv4. Review your infrastructure to locate servers or workstations running kernels potentially affected by this allocation error. Once you have an inventory, coordinate with your system administration teams to plan for standard kernel updates or patches that address memory management stability.

References