CVE-2026-89715
In the Linux kernel, the following vulnerability has been resolved:
NFS/localio: fix ref leak on nfs_uuid_add_file failure
When nfs_uuid_add_file() races with nfs_uuid_put() tearing down uuid->net, it returns -ENXIO without publishing nfl->nfs_uuid via rcu_assign_pointer(). nfs_open_local_fh() then enters its error branch and only releases the slot's file ref and its paired net ref plus its own entry-time net ref, while the close path is a no-op:
nfsd_open_local_fh() returns localio holding a caller-owned +1 nfsd_file reference (from nfsd_file_get() after nfsd_file_acquire_local()) and an entry-time nfsd_net reference (from its first nfsd_net_try_get()) embedded as nf->nf_net.
Leer descripción completaMostrar menos
Both are leaked on the failure path, pinning one nfsd_file (and the underlying struct file, dentry, inode) and one nfsd_net_ref per occurrence, which blocks nfsd_net and netns teardown.
Fix by releasing the caller-owned file ref and its net ref through the existing helper, using a stack-local RCU pointer so the helper can xchg it out, then returning -ENXIO so callers do not dereference a localio whose slot has been cleared:
The trailing nfs_to_nfsd_net_put(net) continues to release the outer net ref, so all three nfsd_net_try_get() increments are balanced on the error branch.
Detalles técnicos trazas, registros y código del informe original
nfs_close_local_fh()
nfs_uuid = rcu_dereference(nfl->nfs_uuid);
if (!nfs_uuid) { rcu_read_unlock(); return; } /* always */
struct nfsd_file __rcu *tmp = RCU_INITIALIZER(localio);
nfs_to_nfsd_file_put_local(pnf);
nfs_to_nfsd_file_put_local(&tmp);
localio = ERR_PTR(-ENXIO);CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-89715",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "fdd015de767977f21892329af5e12276eb80375f",
"lessThan": "5215e734bf7cba18237155f8cb2a0accb60ca339",
"versionType": "git"
},
{
"status": "affected",
"version": "fdd015de767977f21892329af5e12276eb80375f",
"lessThan": "9f59b05423ed381f8cdeaaae4bd6778adcb6865c",
"versionType": "git"
},
{
"status": "affected",
"version": "fdd015de767977f21892329af5e12276eb80375f",
"lessThan": "ca018c19e0ba38975e5ddc3ef8117d5b734313aa",
"versionType": "git"
},
{
"status": "affected",
"version": "55735dc5a0ee0c0fc14cb51e005eae862906a410",
"versionType": "git"
},
{
"status": "affected",
"version": "7cac8a129fc53497f9ee5d66fca55a245d009b97",
"versionType": "git"
},
{
"status": "affected",
"version": "6.15.10",
"lessThan": "6.16",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.16.1",
"lessThan": "6.17",
"versionType": "semver"
}
],
"programFiles": [
"fs/nfs_common/nfslocalio.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.17"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.17",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.18.50",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.4",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"fs/nfs_common/nfslocalio.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-11T20:19:58.993",
"references": [
{
"url": "https://git.kernel.org/stable/c/5215e734bf7cba18237155f8cb2a0accb60ca339",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9f59b05423ed381f8cdeaaae4bd6778adcb6865c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ca018c19e0ba38975e5ddc3ef8117d5b734313aa",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFS/localio: fix ref leak on nfs_uuid_add_file failure\n\nWhen nfs_uuid_add_file() races with nfs_uuid_put() tearing down\nuuid->net, it returns -ENXIO without publishing nfl->nfs_uuid via\nrcu_assign_pointer(). nfs_open_local_fh() then enters its error\nbranch and only releases the slot's file ref and its paired net\nref plus its own entry-time net ref, while the close path is a\nno-op:\n\n nfs_close_local_fh()\n nfs_uuid = rcu_dereference(nfl->nfs_uuid);\n if (!nfs_uuid) { rcu_read_unlock(); return; } /* always */\n\nnfsd_open_local_fh() returns localio holding a caller-owned +1\nnfsd_file reference (from nfsd_file_get() after\nnfsd_file_acquire_local()) and an entry-time nfsd_net reference\n(from its first nfsd_net_try_get()) embedded as nf->nf_net. Both\nare leaked on the failure path, pinning one nfsd_file (and the\nunderlying struct file, dentry, inode) and one nfsd_net_ref per\noccurrence, which blocks nfsd_net and netns teardown.\n\nFix by releasing the caller-owned file ref and its net ref through\nthe existing helper, using a stack-local RCU pointer so the helper\ncan xchg it out, then returning -ENXIO so callers do not\ndereference a localio whose slot has been cleared:\n\n struct nfsd_file __rcu *tmp = RCU_INITIALIZER(localio);\n\n nfs_to_nfsd_file_put_local(pnf);\n nfs_to_nfsd_file_put_local(&tmp);\n localio = ERR_PTR(-ENXIO);\n\nThe trailing nfs_to_nfsd_net_put(net) continues to release the\nouter net ref, so all three nfsd_net_try_get() increments are\nbalanced on the error branch."
}
],
"lastModified": "2026-09-11T20:19:58.993",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}