Affects the Linux kernel's NFS server (widely deployed); can remotely crash servers and disrupt infrastructure.
CVE-2026-89662
Linux kernel nfsd use-after-free allows remote kernel crash (DoS), possible escalation
Is CVE-2026-89662 being exploited?
Not confirmed. CVE-2026-89662 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.68% probability of exploitation in the next 30 days.
How severe is CVE-2026-89662?
CVE-2026-89662 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-89662?
Yes. A fix has been recorded for CVE-2026-89662. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-89662 affect?
CVE-2026-89662 affects Linux kernel (nfsd), NFS servers running affected kernel versions. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-89662?
Apply vendor kernel patches and reboot NFS servers immediately
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Remote attacker can trigger nfsd use-after-free causing kernel NULL dereference and crash (remote DoS); may enable local privilege escalation if further exploited.
Immediate action required
- affected>= 68ef3bc3166468678d5e1fdd216628c35bd1186f and < 42d7954b0a1907d4ef122aef94561952a033cdc3
- affected>= 68ef3bc3166468678d5e1fdd216628c35bd1186f and < bb38ff8b4dafbbd1781ad37cd96722fdf2cd972a
- affected>= 68ef3bc3166468678d5e1fdd216628c35bd1186f and < b8bad5a11416b26cc7fd4b18fba46d75ff636558
- affected>= 68ef3bc3166468678d5e1fdd216628c35bd1186f and < 1ce74d1b7770e69735e8f8e509807af4ff9c8ee7
- affected>= 68ef3bc3166468678d5e1fdd216628c35bd1186f and < a6ead6fff3a7d03e49845f048f7000a2e0d34431
- affected>= 68ef3bc3166468678d5e1fdd216628c35bd1186f and < 4804c58f73a80d12df1de323bf97a164f6ee8743
- affected>= 68ef3bc3166468678d5e1fdd216628c35bd1186f and < 8cf4ff0a7c083dd5e0067f517d63979b74b66649
- affected>= 68ef3bc3166468678d5e1fdd216628c35bd1186f and < 5e2fa29d223a9a1e6a948e40b109d09081d1decd
- affectede294c4c2d33b7307a89cdf31bec08a112d6a9297
- affected797bfd05d4040fbf766198b3cfcc1838002cc890
- affected0f44e9da465ea259b6c9f31a627f3c50a16e1679
- affected>= 4.9.91 and < 4.10
- affected>= 4.14.31 and < 4.15
- affected>= 4.15.14 and < 4.16
- affected4.16
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.