« Volver al listado

CVE-2026-89715

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

NFS/localio: fix ref leak on nfs_uuid_add_file failure

When nfs_uuid_add_file() races with nfs_uuid_put() tearing down uuid->net, it returns -ENXIO without publishing nfl->nfs_uuid via rcu_assign_pointer(). nfs_open_local_fh() then enters its error branch and only releases the slot's file ref and its paired net ref plus its own entry-time net ref, while the close path is a no-op:

nfsd_open_local_fh() returns localio holding a caller-owned +1 nfsd_file reference (from nfsd_file_get() after nfsd_file_acquire_local()) and an entry-time nfsd_net reference (from its first nfsd_net_try_get()) embedded as nf->nf_net.

Leer descripción completaMostrar menos

Both are leaked on the failure path, pinning one nfsd_file (and the underlying struct file, dentry, inode) and one nfsd_net_ref per occurrence, which blocks nfsd_net and netns teardown.

Fix by releasing the caller-owned file ref and its net ref through the existing helper, using a stack-local RCU pointer so the helper can xchg it out, then returning -ENXIO so callers do not dereference a localio whose slot has been cleared:

The trailing nfs_to_nfsd_net_put(net) continues to release the outer net ref, so all three nfsd_net_try_get() increments are balanced on the error branch.

Detalles técnicos trazas, registros y código del informe original
    nfs_close_local_fh()
      nfs_uuid = rcu_dereference(nfl->nfs_uuid);
      if (!nfs_uuid) { rcu_read_unlock(); return; }  /* always */

    struct nfsd_file __rcu *tmp = RCU_INITIALIZER(localio);

    nfs_to_nfsd_file_put_local(pnf);
    nfs_to_nfsd_file_put_local(&tmp);
    localio = ERR_PTR(-ENXIO);

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89715",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "fdd015de767977f21892329af5e12276eb80375f",
              "lessThan": "5215e734bf7cba18237155f8cb2a0accb60ca339",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fdd015de767977f21892329af5e12276eb80375f",
              "lessThan": "9f59b05423ed381f8cdeaaae4bd6778adcb6865c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fdd015de767977f21892329af5e12276eb80375f",
              "lessThan": "ca018c19e0ba38975e5ddc3ef8117d5b734313aa",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "55735dc5a0ee0c0fc14cb51e005eae862906a410",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7cac8a129fc53497f9ee5d66fca55a245d009b97",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.15.10",
              "lessThan": "6.16",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.16.1",
              "lessThan": "6.17",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "fs/nfs_common/nfslocalio.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.17"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.17",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.50",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/nfs_common/nfslocalio.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-11T20:19:58.993",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/5215e734bf7cba18237155f8cb2a0accb60ca339",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9f59b05423ed381f8cdeaaae4bd6778adcb6865c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ca018c19e0ba38975e5ddc3ef8117d5b734313aa",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFS/localio: fix ref leak on nfs_uuid_add_file failure\n\nWhen nfs_uuid_add_file() races with nfs_uuid_put() tearing down\nuuid->net, it returns -ENXIO without publishing nfl->nfs_uuid via\nrcu_assign_pointer().  nfs_open_local_fh() then enters its error\nbranch and only releases the slot's file ref and its paired net\nref plus its own entry-time net ref, while the close path is a\nno-op:\n\n    nfs_close_local_fh()\n      nfs_uuid = rcu_dereference(nfl->nfs_uuid);\n      if (!nfs_uuid) { rcu_read_unlock(); return; }  /* always */\n\nnfsd_open_local_fh() returns localio holding a caller-owned +1\nnfsd_file reference (from nfsd_file_get() after\nnfsd_file_acquire_local()) and an entry-time nfsd_net reference\n(from its first nfsd_net_try_get()) embedded as nf->nf_net.  Both\nare leaked on the failure path, pinning one nfsd_file (and the\nunderlying struct file, dentry, inode) and one nfsd_net_ref per\noccurrence, which blocks nfsd_net and netns teardown.\n\nFix by releasing the caller-owned file ref and its net ref through\nthe existing helper, using a stack-local RCU pointer so the helper\ncan xchg it out, then returning -ENXIO so callers do not\ndereference a localio whose slot has been cleared:\n\n    struct nfsd_file __rcu *tmp = RCU_INITIALIZER(localio);\n\n    nfs_to_nfsd_file_put_local(pnf);\n    nfs_to_nfsd_file_put_local(&tmp);\n    localio = ERR_PTR(-ENXIO);\n\nThe trailing nfs_to_nfsd_net_put(net) continues to release the\nouter net ref, so all three nfsd_net_try_get() increments are\nbalanced on the error branch."
    }
  ],
  "lastModified": "2026-09-11T20:19:58.993",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}