PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-93231 Linux CVE debrief

A vulnerability in the Linux kernel's lockd subsystem has been addressed. The nlmsvc_match_ip() function had its arguments reversed, causing locks not to be released when requested by IP address via /proc/fs/nfsd/unlock_ip. This issue was introduced in a specific commit and has been resolved. The fix ensures that locks are properly released, preventing potential denial-of-service attacks. System administrators and security teams should review and apply kernel updates to prevent lockd issues.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-24
Original CVE updated
2026-10-03
Advisory published
2026-09-24
Advisory updated
2026-10-03

Who should care

Linux kernel maintainers, administrators of systems using NFS, and security teams responsible for patching and vulnerability management should be aware of this vulnerability and take necessary actions to prevent lockd issues. System administrators should review and apply kernel updates to ensure the fix is deployed. Security teams should monitor system logs for potential lockd-related errors and implement compensating controls for exposed systems.

Why it matters

A fix was applied to the Linux kernel to address a vulnerability in the lockd subsystem. The vulnerability could prevent locks from being released when requested by IP address.

  • Verify and apply kernel updates to prevent lockd issues
  • Review system logs for potential lockd problems
  • Ensure proper validation of /proc/fs/nfsd/unlock_ip usage

Technical summary

The nlmsvc_match_ip() function in the Linux kernel's lockd subsystem had its arguments reversed, preventing locks from being released when requested by IP address. This has been fixed in the kernel. The fix addresses the issue by swapping the arguments to ensure proper lock release. The vulnerability could be exploited to cause denial-of-service attacks. Technical teams should review and apply kernel updates to ensure the fix is deployed. The fix is specific to the Linux kernel's lockd subsystem and does not affect other kernel components.

Defensive priority

Verify and apply kernel updates to ensure the fix is deployed.

Recommended defensive actions

  • Verify kernel version and apply updates if necessary
  • Review system logs for potential lockd issues
  • Ensure /proc/fs/nfsd/unlock_ip usage is properly validated
  • Monitor system logs for lockd-related errors
  • Perform regular vulnerability scans to detect potential issues
  • Implement compensating controls for exposed systems
  • Track exceptions and retest remediated assets

Evidence notes

The CVE record and source references indicate a fix was applied to the Linux kernel to address the argument reversal in nlmsvc_match_ip(). The fix was introduced to prevent locks from not being released when requested by IP address. The source references provide additional information on the Linux kernel fix. Evidence is limited to public CVE and NVD records.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-93231 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-93231

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-93231 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93231

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/0d72e78c9d38d5377a059a4837f82b65b91cdcf6

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/21bcb609e0ab1dd60f39ca3498f85808933bcc9f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b9060689f49dc663e9a3d069c4a65ff63a836e66

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/d34c2ac447fe0490ede828e0143e2cbcb59e6c77

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.