Critical Linux kernel vulnerability in nfsd (widely deployed); can crash or allow kernel compromise on NFS servers—broad operational impact for organizations running NFS.
CVE-2026-89708
NFS server (nfsd) use-after-free enables remote kernel crash or compromise
Is CVE-2026-89708 being exploited?
Not confirmed. CVE-2026-89708 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.43% probability of exploitation in the next 30 days.
How severe is CVE-2026-89708?
CVE-2026-89708 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-89708?
Yes. A fix has been recorded for CVE-2026-89708. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-89708 affect?
CVE-2026-89708 affects Linux kernel nfsd (NFSv4/NFSv4.1) on servers, Distributions using affected kernels; check vendor kernels. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-89708?
Apply vendor/kernel security updates immediately and reboot affected hosts
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Remote use-after-free in nfsd via NFSv4 callbacks can cause kernel panic (DoS) or enable privilege escalation/remote kernel compromise.
Immediate action required
- affected>= dcbeaa68dbbdacbbb330a86c7fc95a28473fc209 and < f164eb52b6f3cbf40f07fe379f9f421f88e02f76
- affected>= dcbeaa68dbbdacbbb330a86c7fc95a28473fc209 and < 13bdd486c3aad4fc19e6d8b9c3556a4b4c190b25
- affected>= dcbeaa68dbbdacbbb330a86c7fc95a28473fc209 and < 01c5d5f58a5db9b0ee5afba2e49d3157788687b2
- affected2.6.38
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.