{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown  After a DESTROY_SESSION the per-session teardown path can free a session while rpciod still holds an inflight callback rpc_task that dereferences clp-\u003ecl_cb_session.  nfsd4_probe_callback_sync() flushes cl_callback_wq, but once nfsd4_run_cb_work() has called rpc_call_async() the rpc_task lives on rpciod; flushing the workqueue does not wait for it.  rpc_shutdown_client() does drain rpciod tasks, but uses a 1-second wait_event_timeout — tasks stuck in rpc_delay() (e.g. 2-second NFS4ERR_DELAY retries) can outlive the drain.      destroy path                       rpciod     ------------                       ------     unhash_session(ses)     nfsd4_probe_callback_sync(clp)       flush_workqueue(cl_callback_wq)       /* returns; rpc_task still live */     nfsd4_put_session_locked(ses)     free_session(ses) -\u003e kfree(ses)                                        nfsd4_cb_sequence_done()                                          reads cb_clp-\u003ecl_cb_session                                          /* freed slab */  A second window exists in nfsd4_process_cb_update().  When __nfsd4_find_backchannel() returns NULL because unhash_session() has already removed the destroyed session from cl_sessions, setup_callback_client() takes the v4.1 early return so clp-\u003ecl_cb_session = ses never fires and the field retains a pointer to the about-to-be-freed session.  Fix both by converting cl_cb_session to an RCU-protected pointer:    - Move the cl_cb_session = ses assignment in setup_callback_client()     to after rpc_create() succeeds, so it is only published when a     working backchannel exists.  Clear cl_cb_session on the error     return in nfsd4_process_cb_update().  Both stores use     rcu_assign_pointer().    - Annotate cl_cb_session with __rcu.  All rpciod-side readers use     rcu_read_lock()/rcu_dereference() and check for NULL, bailing to     the appropriate error or requeue path:     encode_cb_sequence4args(), decode_cb_sequence4resok(),     nfsd41_cb_get_slot(), nfsd41_cb_release_slot(),     nfsd4_cb_prepare(), and nfsd4_cb_sequence_done().    - Switch __free_session() from kfree() to kfree_rcu() so the     session slab is not reclaimed until after an RCU grace period,     guaranteeing that rpciod readers inside rcu_read_lock() never     dereference freed memory.    - Pass the session pointer to the nfsd_cb_seq_status and     nfsd_cb_free_slot tracepoints instead of having them re-read     cl_cb_session.    - nfsd4_cb_prepare() calls rpc_exit() when the session is NULL,     routing through the done/release path to requeue the callback.",
  "id": "DEBIAN-CVE-2026-89708",
  "modified": "2026-09-14T08:47:45.071331660Z",
  "published": "2026-09-11T20:19:58.140Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-89708"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-89708"
  ]
}