Home / Security / Advisories / NTAP-20261002-0016
NTAP-20261002-0016 — CVE-2026-89712 Linux Kernel Vulnerability in NetApp Products
Published 2026-10-02 · Updated 2026-10-02 · Status: Interim · Exploitation: Public · Severity: CRITICAL 9.8 · ONTAP affected: Yes
Product family: Baseboard management controllers · Active IQ Unified Manager · Brocade SAN firmware · ONTAP · Other NetApp products · NetApp Console / BlueXP · SolidFire / NetApp HCI · SnapCenter | ONTAP-relevant | highest CVSS: 9.8
CVEs in this advisory
- CVE-2026-89712 — CRITICAL · CVSS 9.8 · site index
What the CVE records say
CVE-2026-89712 — In the Linux kernel, the following vulnerability has been resolved: NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock nfsd4_ssc_expire_umount() walks nn->nfsd_ssc_mount_list with list_for_each_entry_safe(ni, tmp, ...). For each expired entry it sets nsui_busy = true, drops nfsd_ssc_lock to run mntput() on the source vfsmount, then reacquires the lock to list_del + kfree the entry and continue iterating via the macro's saved tmp pointer. The nsui_busy flag protects the current ni from concurrent nfsd4_ssc_setup_dul() finders during the lock-drop window, but it does not pin tmp. Another nfsd RPC thread that fails its source- server mount and reaches nfsd4_ssc_cancel_dul() will, during that same window, take nfsd_ssc_lock, list_del + kfree its own ssc_umount item, and release the lock. If that item is the saved tmp of the expire walk, the next iteration dereferences a freed nfsd4_ssc_umount_item. Restart the walk from the head after the mntput() unlock window so no saved next pointer survives the lock-drop. The list is bounded by the number of active inter-server source mounts (typically small) and the expire delayed-work runs periodically rather than per-IO, so the restart is cheap.
Impact
Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data or Denial of Service (DoS).
Affected products
- AFF Baseboard Management Controller (BMC) - A700s
- Active IQ Unified Manager for VMware vSphere
- Brocade Fabric Operating System Firmware
- Cloud Volumes ONTAP Mediator
- FAS/AFF BIOS - A900/9500
- FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400
- FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250
- NetApp Console Agent OVA
- NetApp HCI Baseboard Management Controller (BMC) - H610S
- NetApp SolidFire & HCI Management Node
- NetApp SolidFire & HCI Storage Node (Element Software)
- ONTAP Select Deploy administration utility
References
What to do
- Check the affected products listed above against the official advisory's affected-versions table — that is where the exact ONTAP 9 release, ONTAP tool, or management product versions are named.
- If affected and a fixed release exists, plan the upgrade — see the ONTAP upgrade runbook.
- If exploitation is listed as "active", treat remediation as urgent and review exposure (management LIFs, ONTAP S3, SnapMirror endpoints).
- Harden in parallel: security hardening baseline and ransomware protection on ONTAP.
Related reading
- Common ONTAP problems (FAQ) — plain-language symptoms and fixes
- ONTAP security hardening — baseline lockdown guidance
- Ransomware protection on ONTAP — SnapLock, SnapMirror vaulting, Anomaly Detection
- ONTAP error messages index — EMS/WAFL/NFS/SnapMirror messages
- Every NetApp advisory published in 2026