CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-74730

criticalCVSS 9.8covered by 2 sourcesfirst seen 2026-08-11
In the Linux kernel, the following vulnerability has been resolved: NFS: Pin the 'struct nfs_server' during a FREE_STATEID call Dan Aloni reports that he was able to hit a use-after-free bug if a FREE_STATEID operation gets delayed for whatever reason. Fix this by bumping the refcount of the 'struct nfs_server' object for the duration of the FREE_STATEID so it doesn't get cleaned up from underneath us while operations are still in flight.

CSIRTS triage

What
NFS does not pin the nfs_server structure during FREE_STATEID calls, risking use-after-free or reference counting errors.
Who is affected
Linux systems using NFS client functionality.
Urgency
Moderate; CVSS 5.9 and use-after-free potential warrant prompt patching.
Action
Apply kernel patch or upgrade to a Linux version with NFS stateid locking fix.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-74730

Get an email if CVE-2026-74730 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-74730

CVE.org record

Embed the live status

CVE-2026-74730 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-74730 status](https://www.csirts.com/badge/CVE-2026-74730)](https://www.csirts.com/cve/CVE-2026-74730)