CVE-2026-89715
Received Received - Intake

Memory Leak in Linux Kernel NFS LocalIO

Vulnerability report for CVE-2026-89715, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: NFS/localio: fix ref leak on nfs_uuid_add_file failure When nfs_uuid_add_file() races with nfs_uuid_put() tearing down uuid->net, it returns -ENXIO without publishing nfl->nfs_uuid via rcu_assign_pointer(). nfs_open_local_fh() then enters its error branch and only releases the slot's file ref and its paired net ref plus its own entry-time net ref, while the close path is a no-op: nfs_close_local_fh() nfs_uuid = rcu_dereference(nfl->nfs_uuid); if (!nfs_uuid) { rcu_read_unlock(); return; } /* always */ nfsd_open_local_fh() returns localio holding a caller-owned +1 nfsd_file reference (from nfsd_file_get() after nfsd_file_acquire_local()) and an entry-time nfsd_net reference (from its first nfsd_net_try_get()) embedded as nf->nf_net. Both are leaked on the failure path, pinning one nfsd_file (and the underlying struct file, dentry, inode) and one nfsd_net_ref per occurrence, which blocks nfsd_net and netns teardown. Fix by releasing the caller-owned file ref and its net ref through the existing helper, using a stack-local RCU pointer so the helper can xchg it out, then returning -ENXIO so callers do not dereference a localio whose slot has been cleared: struct nfsd_file __rcu *tmp = RCU_INITIALIZER(localio); nfs_to_nfsd_file_put_local(pnf); nfs_to_nfsd_file_put_local(&tmp); localio = ERR_PTR(-ENXIO); The trailing nfs_to_nfsd_net_put(net) continues to release the outer net ref, so all three nfsd_net_try_get() increments are balanced on the error branch.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-09-12
AI Q&A
2026-09-12
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux_kernel nfs *-*

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a reference leak in the NFS/localio subsystem. When a specific function fails, it doesn't properly release resources, causing file and network references to remain allocated. This leads to pinned nfsd_file and nfsd_net structures, blocking teardown processes.

Detection Guidance

This vulnerability is specific to the Linux kernel's NFS implementation and involves a reference leak in the nfs_uuid_add_file function. Detection requires kernel-level inspection and is not typically done via standard network commands. You would need to check kernel logs for related errors or use kernel debugging tools to identify leaked references in NFS operations.

Impact Analysis

The vulnerability can cause resource exhaustion by leaking file and network references. This may lead to system instability, degraded performance, or inability to properly shut down network namespaces and NFS services due to pinned resources.

Mitigation Strategies

Apply the latest Linux kernel patches that address this issue. Since this is a kernel-level vulnerability, updating to a patched kernel version is the primary mitigation. Monitor vendor advisories for kernel updates and ensure your NFS services are restarted after patching.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89715. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart