CVE-2026-89484
Last modified
CVE-2026-89484 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: lockd: fix NULL dereference on lockowner allocation failure nlmclnt_locks_init_private() installs NLM file lock operations even when nlmclnt_find_lockowner() fails to allocate a lockowner. nlmclnt_proc() then returns -ENOMEM, but the VFS still tears down the partially initialized file_lock and calls locks_release_private(). That invokes nlmclnt_locks_release_private(), which dereferences fl->fl_u.nfs_fl.owner and crashes because the owner was never installed. Clear fl_ops before attempting to initialize the NLM private state, and install the NLM lock operations only after a lockowner has been allocated successfully..
Description
In the Linux kernel, the following vulnerability has been resolved: lockd: fix NULL dereference on lockowner allocation failure nlmclnt_locks_init_private() installs NLM file lock operations even when nlmclnt_find_lockowner() fails to allocate a lockowner. nlmclnt_proc() then returns -ENOMEM, but the VFS still tears down the partially initialized file_lock and calls locks_release_private(). That invokes nlmclnt_locks_release_private(), which dereferences fl->fl_u.nfs_fl.owner and crashes because the owner was never installed. Clear fl_ops before attempting to initialize the NLM private state, and install the NLM lock operations only after a lockowner has been allocated successfully.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < 07adfbb3de7529f58ca708a97ead7fa4fdb71056; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < d662f7fc04fde305a27f304b3cd19b614d366839; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < 51af080ca4e553256c59a75a877b9b4fff828311; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < 4c7fc129db061c7daab841c4f3c342d894832362 |
| Linux | Linux | 2.6.12 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-89484?
How severe is CVE-2026-89484?
How do I fix CVE-2026-89484?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-89479In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-8948Same-origin policy bypass in the DOM: Networking component. …9.1
- CVE-2026-89480In the Linux kernel, the following vulnerability has been re…7.5
- CVE-2026-89481In the Linux kernel, the following vulnerability has been re…7.5
- CVE-2026-89482In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-89483In the Linux kernel, the following vulnerability has been re…7.5
- CVE-2026-89485In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-89486In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-89487In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-89488In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-89489In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-8949Integer overflow in the Widget: Win32 component. This vulner…7.5
Are you affected by CVE-2026-89484?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
