CVE-2026-22989

Updated on 23 Jan 2026

Severity

5.5 Medium severity

Details

CVSS score
5.5
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved:

nfsd: check that server is running in unlock_filesystem

If we are trying to unlock the filesystem via an administrative interface and nfsd isn’t running, it crashes the server. This happens currently because nfsd4_revoke_states() access state structures (eg., conf_id_hashtbl) that has been freed as a part of the server shutdown.

[ 59.465072] Call trace: [ 59.465308] nfsd4_revoke_states+0x1b4/0x898 [nfsd] (P) [ 59.465830] write_unlock_fs+0x258/0x440 [nfsd] [ 59.466278] nfsctl_transaction_write+0xb0/0x120 [nfsd] [ 59.466780] vfs_write+0x1f0/0x938 [ 59.467088] ksys_write+0xfc/0x1f8 [ 59.467395] __arm64_sys_write+0x74/0xb8 [ 59.467746] invoke_syscall.constprop.0+0xdc/0x1e8 [ 59.468177] do_el0_svc+0x154/0x1d8 [ 59.468489] el0_svc+0x40/0xe0 [ 59.468767] el0t_64_sync_handler+0xa0/0xe8 [ 59.469138] el0t_64_sync+0x1ac/0x1b0

Ensure this can’t happen by taking the nfsd_mutex and checking that the server is still up, and then holding the mutex across the call to nfsd4_revoke_states().

Details

Affected product:
AlmaLinux 9.2 ESU , TuxCare 9.6 ESU
Affected packages:
kernel @ 5.14.0 (+1 more)

Fixes

KernelCare state

Live-patch status from KernelCare for each operating system.

Operating system Status Covered kernels
AlmaLinux 9.6 ESU Released
11 kernels
  • 5.14.0-570.62.1.el9_6.tuxcare.1.els1
  • 5.14.0-570.62.1.el9_6.tuxcare.1.els2
  • 5.14.0-570.62.1.el9_6.tuxcare.1.els3
  • 5.14.0-570.62.1.el9_6.tuxcare.1.els4
  • 5.14.0-570.62.1.el9_6.tuxcare.1.els5
  • 5.14.0-570.62.1.el9_6.tuxcare.1.els6
  • 5.14.0-570.62.1.el9_6.tuxcare.1.els7
  • 5.14.0-570.62.1.el9_6.tuxcare.5.els1
  • 5.14.0-570.62.1.el9_6.tuxcare.5.els2
  • 5.14.0-570.62.1.el9_6.tuxcare.5.els3
  • 5.14.0-570.62.1.el9_6.tuxcare.5.els4
Debian 13 Planned
Oracle Linux 8 UEK 7 Released
28 kernels
  • 5.15.0-309.180.4.el8uek
  • 5.15.0-309.180.4.2.el8uek
  • 5.15.0-310.184.5.2.el8uek
  • 5.15.0-310.184.5.3.el8uek
  • 5.15.0-311.185.9.el8uek
  • 5.15.0-312.187.5.el8uek
  • 5.15.0-312.187.5.1.el8uek
  • 5.15.0-312.187.5.2.el8uek
  • 5.15.0-312.187.5.3.el8uek
  • 5.15.0-313.189.5.1.el8uek
  • 5.15.0-313.189.5.2.el8uek
  • 5.15.0-313.189.5.3.el8uek
  • 5.15.0-314.193.5.3.el8uek
  • 5.15.0-314.193.5.4.el8uek
  • 5.15.0-314.193.5.5.el8uek
  • 5.15.0-315.196.5.1.el8uek
  • 5.15.0-315.196.5.2.el8uek
  • 5.15.0-316.196.4.1.el8uek
  • 5.15.0-316.196.4.2.el8uek
  • 5.15.0-317.197.5.1.el8uek
  • 5.15.0-317.197.5.2.el8uek
  • 5.15.0-318.199.3.2.el8uek
  • 5.15.0-318.199.3.2.1.el8uek
  • 5.15.0-319.201.4.2.el8uek
  • 5.15.0-319.201.4.3.el8uek
  • 5.15.0-319.201.4.4.el8uek
  • 5.15.0-319.201.4.6.el8uek
  • 5.15.0-318.199.3.6.el8uek
Oracle Linux 9 UEK 7 Released
28 kernels
  • 5.15.0-309.180.4.el9uek
  • 5.15.0-309.180.4.2.el9uek
  • 5.15.0-310.184.5.2.el9uek
  • 5.15.0-310.184.5.3.el9uek
  • 5.15.0-311.185.9.el9uek
  • 5.15.0-312.187.5.el9uek
  • 5.15.0-312.187.5.1.el9uek
  • 5.15.0-312.187.5.2.el9uek
  • 5.15.0-312.187.5.3.el9uek
  • 5.15.0-313.189.5.1.el9uek
  • 5.15.0-313.189.5.2.el9uek
  • 5.15.0-313.189.5.3.el9uek
  • 5.15.0-314.193.5.3.el9uek
  • 5.15.0-314.193.5.4.el9uek
  • 5.15.0-314.193.5.5.el9uek
  • 5.15.0-315.196.5.1.el9uek
  • 5.15.0-315.196.5.2.el9uek
  • 5.15.0-316.196.4.1.el9uek
  • 5.15.0-316.196.4.2.el9uek
  • 5.15.0-317.197.5.1.el9uek
  • 5.15.0-317.197.5.2.el9uek
  • 5.15.0-318.199.3.2.el9uek
  • 5.15.0-318.199.3.2.1.el9uek
  • 5.15.0-319.201.4.2.el9uek
  • 5.15.0-319.201.4.3.el9uek
  • 5.15.0-319.201.4.4.el9uek
  • 5.15.0-319.201.4.6.el9uek
  • 5.15.0-318.199.3.6.el9uek