CVE-2026-90036 | Linux Kernel up to 6.18.50/7.2.4 NFSD nfs4_put_stateowner use after free
A vulnerability was found in Linux Kernel up to 6.18.50/7.2.4. It has been declared as very critical. This affects the function nfs4_put_stateowner of the component NFSD. Executing a manipulation can lead to use after free.
This vulnerability is registered as CVE-2026-90036. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.