In the Linux kernel, the following vulnerability has been resolved:
lockd: fix NULL dereference on lockowner allocation failure
nlmclnt_locks_init_private() installs NLM file lock operations even when
nlmclnt_find_lockowner() fails to allocate a lockowner. nlmclnt_proc()
then returns -ENOMEM, but the VFS still tears down the partially
initialized file_lock and calls locks_release_private().
That invokes nlmclnt_locks_release_private(), which dereferences
fl->fl_u.nfs_fl.owner and crashes because the owner was never installed.
Clear fl_ops before attempting to initialize the NLM private state, and
install the NLM lock operations only after a lockowner has been allocated
successfully.
CVE-2026-89484
NONE
EPSS 0.21%
Updated Sep 11, 2026
Linux
https://git.kernel.org/stable/c/07adfbb3de7529f58ca708a97ead7fa4fdb71056
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/4c7fc129db061c7daab841c4f3c342d894832362
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/51af080ca4e553256c59a75a877b9b4fff828311
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/d662f7fc04fde305a27f304b3cd19b614d366839
416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVE Details
CVE ID
CVE-2026-89484
Published Date
Sep 11, 2026
Vendor
Linux
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.21%
Likelihood of exploitation in next 30 days
Percentile:
9.6th percentile (higher than 9.6% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory