CVE-2026-89715
Last modified
CVE-2026-89715 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: NFS/localio: fix ref leak on nfs_uuid_add_file failure When nfs_uuid_add_file() races with nfs_uuid_put() tearing down uuid->net, it returns -ENXIO without publishing nfl->nfs_uuid via rcu_assign_pointer(). nfs_open_local_fh() then enters its error branch and only releases the slot's file ref and its paired net ref plus its own entry-time net ref, while the close path is a no-op: nfs_close_local_fh() nfs_uuid = rcu_dereference(nfl->nfs_uuid); if (!nfs_uuid) { rcu_read_unlock(); return; } /* always */ nfsd_open_local_fh() returns localio holding a caller-owned +1 nfsd_file reference (from nfsd_file_get() after nfsd_file_acquire_local()) and an entry-time nfsd_net reference (from its first nfsd_net_try_get()) embedded as nf->nf_net.
Description
In the Linux kernel, the following vulnerability has been resolved: NFS/localio: fix ref leak on nfs_uuid_add_file failure When nfs_uuid_add_file() races with nfs_uuid_put() tearing down uuid->net, it returns -ENXIO without publishing nfl->nfs_uuid via rcu_assign_pointer(). nfs_open_local_fh() then enters its error branch and only releases the slot's file ref and its paired net ref plus its own entry-time net ref, while the close path is a no-op: nfs_close_local_fh() nfs_uuid = rcu_dereference(nfl->nfs_uuid); if (!nfs_uuid) { rcu_read_unlock(); return; } /* always */ nfsd_open_local_fh() returns localio holding a caller-owned +1 nfsd_file reference (from nfsd_file_get() after nfsd_file_acquire_local()) and an entry-time nfsd_net reference (from its first nfsd_net_try_get()) embedded as nf->nf_net. Both are leaked on the failure path, pinning one nfsd_file (and the underlying struct file, dentry, inode) and one nfsd_net_ref per occurrence, which blocks nfsd_net and netns teardown. Fix by releasing the caller-owned file ref and its net ref through the existing helper, using a stack-local RCU pointer so the helper can xchg it out, then returning -ENXIO so callers do not dereference a localio whose slot has been cleared: struct nfsd_file __rcu *tmp = RCU_INITIALIZER(localio); nfs_to_nfsd_file_put_local(pnf); nfs_to_nfsd_file_put_local(&tmp); localio = ERR_PTR(-ENXIO); The trailing nfs_to_nfsd_net_put(net) continues to release the outer net ref, so all three nfsd_net_try_get() increments are balanced on the error branch.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= fdd015de767977f21892329af5e12276eb80375f, < 5215e734bf7cba18237155f8cb2a0accb60ca339; >= fdd015de767977f21892329af5e12276eb80375f, < 9f59b05423ed381f8cdeaaae4bd6778adcb6865c; >= fdd015de767977f21892329af5e12276eb80375f, < ca018c19e0ba38975e5ddc3ef8117d5b734313aa; 55735dc5a0ee0c0fc14cb51e005eae862906a410; 7cac8a129fc53497f9ee5d66fca55a245d009b97; >= 6.15.10, < 6.16; >= 6.16.1, < 6.17 |
| Linux | Linux | 6.17 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-89715?
How severe is CVE-2026-89715?
How do I fix CVE-2026-89715?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-8971Same-origin policy bypass in the Networking: JAR component. …6.5
- CVE-2026-89710In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89711In the Linux kernel, the following vulnerability has been re…8.2
- CVE-2026-89712In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-89713In the Linux kernel, the following vulnerability has been re…9.1
- CVE-2026-89714In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89716In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89717In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89718In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89719In the Linux kernel, the following vulnerability has been re…
- CVE-2026-8972Privilege escalation in the WebRTC: Audio/Video component. T…8.8
- CVE-2026-89720In the Linux kernel, the following vulnerability has been re…7.7
Are you affected by CVE-2026-89715?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
