Linux kernel NFS server flaw enables remote kernel-level RCE on servers running nfsd; affects core infrastructure used widely across organizations.
CVE-2026-89658
Use-after-free in Linux NFSv4 server enables remote kernel code execution.
Is CVE-2026-89658 being exploited?
Not confirmed. CVE-2026-89658 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.61% probability of exploitation in the next 30 days.
How severe is CVE-2026-89658?
CVE-2026-89658 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-89658?
Yes. A fix has been recorded for CVE-2026-89658. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-89658 affect?
CVE-2026-89658 affects Linux kernel (nfsd, NFSv4.0), Linux servers running affected kernel versions. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-89658?
Apply vendor/kernel patch immediately; or disable NFSv4/block NFS ports until patched.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Remote kernel code execution via NFSv4.0 state cleanup use-after-free; attacker can crash or gain root on hosts running nfsd.
Immediate action required
- affected>= d688d8585e6bea5e4e37f7497feea93b6b0a469c and < 0ae0d2b5c5a1b39c0b3c15d96b32a5b0c583d519
- affected>= d688d8585e6bea5e4e37f7497feea93b6b0a469c and < b413ec5b23e3445dc9c4f273116078e2d4747626
- affected>= d688d8585e6bea5e4e37f7497feea93b6b0a469c and < 81cf7f1413862f87b078920c838460a6a88aa030
- affected>= d688d8585e6bea5e4e37f7497feea93b6b0a469c and < 7b4f8a1586c42d3afc3c0ac779af2db7ab1a5c55
- affected6.9
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.