{"id":"CVE-2026-90151","url":"https://www.cyber-defence.io/tools/cve/CVE-2026-90151","generatedAt":"2026-09-20T12:35:46.276Z","title":"In the Linux kernel, the following vulnerability has been resolved: NFSv4: remove callback IDR entry on client allocation failure nfs4_alloc_client() allocates an NFSv4.0 callback identifier before it finishes setting up the client.","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nNFSv4: remove callback IDR entry on client allocation failure\n\nnfs4_alloc_client() allocates an NFSv4.0 callback identifier before it\nfinishes setting up the client. If any later initialization step fails,\nthe error path frees the nfs_client directly with nfs_free_client(). That\nbypasses nfs_put_client(), which is where the callback IDR entry is\nremoved during normal teardown.\n\nA failed allocation can therefore leave cb_ident_idr pointing at a freed\nnfs_client. A later NFSv4.0 callback lookup by cb_ident would find the\nstale pointer and take a reference to it.\n\nMake the callback IDR removal helper callable by the allocation failure\npath, and remove the callback identifier before freeing the client.\n\nThis was found by a local static-analysis checker for publish-before-free\nlifetime bugs and confirmed by manual inspection.","published":"2026-09-17T17:17:08.000Z","lastModified":"2026-09-18T18:17:44.000Z","status":"Received","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","cvss":{"version":"3.1","score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cwe":[],"affected":[],"epss":{"score":0.00739,"percentile":0.53074,"date":"2026-09-19","history":[]},"kev":{"listed":false},"exploits":{"count":0,"verified":false,"firstPublished":null,"source":"Exploit-DB (https://gitlab.com/exploit-database/exploitdb)","entries":[]},"verdict":{"level":"high","text":"High impact if exploited, but EPSS currently rates exploitation as unlikely (0.74%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit."},"changes":[],"references":[{"url":"https://git.kernel.org/stable/c/3f2387e8bfbc4efda5d77c3a11a028d0a119c48f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5891c03e150920618db0e9c4ea2d772abacdcfd1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/68c721391b761dbe38d5b0094d2bb6e8489ad92b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7c4812eb96bdcafb31a65b12f2aa96659429d1d4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/80b1c3d5a881f7d9081aa9f46da9742878a0f893","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9bfdd0f591307b5198826a0e7a5b2f35f87acd2d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d05c2007b3d84ccba11dc6e9cb3202768cc72f14","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fc95ca82d5ae598c428ab5a00ae69f8526d59371","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"sources":{"nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-90151","epss":"https://www.first.org/epss/","kev":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","exploitdb":"https://www.exploit-db.com/"},"licence":"CC BY 4.0 — link back to the CVE Explorer if you publish the results; upstream data remains subject to its own terms."}