CVE-2026-89667
Received Received - Intake

Race Condition in Linux Kernel NFSd File Cache Handling

Vulnerability report for CVE-2026-89667, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache The shrinker, GC worker, and fsnotify/lease callbacks can unhash an nfsd_file from the rhashtable and then call nfsd_file_dispose_list_delayed() to move it to the per-net dispose list. If nfsd_file_cache_shutdown_net() runs concurrently, its rhashtable walk misses the already-unhashed file, and its drain of the per-net dispose list can run before the file has been queued. The file then sits on the per-net list with no thread to drain it, leaking both the file and its associated state. The GC worker and shrinker already hold nfsd_gc_lock while walking the LRU, but in the original code they release it before calling nfsd_file_dispose_list_delayed(). The fsnotify/lease path (nfsd_file_close_inode) has no synchronization at all. Fix this by: 1. Widening nfsd_gc_lock in both nfsd_file_gc() and nfsd_file_lru_scan() to cover the nfsd_file_dispose_list_delayed() call. 2. Wrapping nfsd_file_close_inode() in nfsd_gc_lock so that all three callers of nfsd_file_dispose_list_delayed() hold the lock. 3. Adding a spin_lock/unlock(nfsd_gc_lock) barrier in nfsd_file_cache_shutdown_net() after the purge, so that any in-progress disposal has fully completed before the per-net list is drained. All operations inside the lock are non-sleeping (rhashtable lookups, atomic bit/refcount ops, list moves, svc_wake_up), so the spinlock is appropriate.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-09-12
AI Q&A
2026-09-12
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a race condition vulnerability in the Linux kernel's NFS server (nfsd) file cache management. It occurs when the shrinker, garbage collector (GC), or fsnotify/lease callbacks unhash an nfsd_file from the rhashtable and attempt to dispose of it. If the per-net shutdown process runs concurrently, it may miss the file, leading to a leak where the file and its state remain indefinitely on a disposal list.

Detection Guidance

This vulnerability is specific to the Linux kernel's NFS server implementation and requires kernel-level inspection. Detection involves checking for kernel logs or running commands that inspect NFS file cache behavior. Use 'dmesg | grep nfsd' to check for related errors or warnings in kernel logs. Monitor for memory leaks or hung processes related to nfsd_file_cache.

Impact Analysis

This vulnerability can cause memory leaks in the Linux kernel's NFS server, potentially leading to resource exhaustion. Systems running NFS services may experience degraded performance or crashes due to unmanaged memory usage.

Mitigation Strategies

Apply the latest kernel security patches that include the fix for this issue. Restart the NFS server service to ensure the patched kernel is active. Monitor system performance and logs for any signs of the race condition or memory leaks after applying the patch.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89667. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart