{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89670","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.746Z","datePublished":"2026-09-11T19:45:55.846Z","dateUpdated":"2026-09-13T06:32:52.764Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:32:52.764Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: hold rcu across localio cmpxchg retry\n\nnfsd_file objects are freed via call_rcu (filecache.c:296), and\nnfsd_file_slab is created without SLAB_TYPESAFE_BY_RCU\n(KMEM_CACHE(nfsd_file, 0) at filecache.c:789), so the slab page\nbacking a freed nfsd_file becomes freely reclaimable once the RCU\ngrace period elapses.\n\nThe again: retry block in nfsd_open_local_fh() loads a pointer with\ncmpxchg and then calls nfsd_file_get(new) (which is\nrefcount_inc_not_zero) without holding rcu_read_lock. The sole caller\nnfs_open_local_fh() drops rcu_read_lock before invoking this helper,\nso no outer reader-side critical section covers the load.\n\n    CPU 0 (nfsd_open_local_fh)        CPU 1 (nfsd_file_put_local)\n    -----                             -----\n    new = cmpxchg(pnf, NULL, ...)\n                                      nf = xchg(pnf, NULL)\n                                      nfsd_file_put(nf)\n                                        last ref -> call_rcu()\n                                      /* grace period elapses;\n                                         slab page recycled */\n    nfsd_file_get(new)\n      refcount_inc_not_zero(&new->nf_ref)\n      /* operates on recycled memory */\n\nA non-zero word at the nf_ref offset of the recycled object makes the\nrefcount bump appear to succeed, and the caller then dereferences\nnew->nf_net and new->nf_file out of freed memory.\n\nFix by taking rcu_read_lock() immediately before the cmpxchg and\nreleasing it on all three exits of the if (new) block: the goto-again\nretry, the lost-race cleanup path, and the install-succeeded path.\nnfsd_file_put() and nfsd_net_put() stay outside the RCU section so\nthey remain free to block."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - nfsd_open_local_fh is invoked only from the NFS client's LOCALIO path (nfs_generic_pg_pgios/nfs_commit_list → nfs_local_open_fh) after a same-host UUID handshake; a remote NFS peer never reaches this cmpxchg retry, so exploitation requires local access to a loopback NFS mount.\nAC:L - The attacker controls both sides of the race: concurrent read/write/commit syscalls enter nfsd_open_local_fh while close/put_nfs_open_context runs nfsd_file_put_local on the same nfs_file_localio slot; the sequence is repeatable at will and can be widened by preemption.\nPR:L - Any unprivileged local user who can open files on a LOCALIO-enabled NFS mount can reach nfs_generic_pg_pgios → nfsd_open_local_fh with no capability check; starting nfsd or creating the mount is a deployment precondition, not a privilege the attacker must hold.\nUI:N - The attacker triggers the use-after-free from their own threads via I/O and close syscalls; no separate victim action is required once the LOCALIO mount exists.\nS:U - The use-after-free corrupts nfsd_file slab objects in the host kernel, which is standard kernel memory corruption within one security authority, not a VM escape, IOMMU bypass, or sandbox boundary crossing.\nC:H - nfsd_file is freed via call_rcu without SLAB_TYPESAFE_BY_RCU, so after the grace period nfsd_file_get and later nf_file/nf_net dereferences operate on recycled memory, enabling an arbitrary kernel read or disclosure of another exported file's contents.\nI:H - refcount_inc_not_zero writes into the recycled nfsd_file, and the stale pointer is then used for write_iter, corrupting another object's refcount and enabling a follow-on premature free and control-flow hijack.\nA:H - Use-after-free on the nfsd_file slab causes slab corruption, refcount warnings, and oops/panic when nf_file is taken from freed memory, which is a repeatable local kernel denial of service."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfsd/localio.c"],"versions":[{"version":"e6f7e1487ab528a6c653bd0d42812ff2942846cd","lessThan":"763c0bad872368304db718f79af7e93048885c67","status":"affected","versionType":"git"},{"version":"e6f7e1487ab528a6c653bd0d42812ff2942846cd","lessThan":"559570f91a7d4d199a72105e4980bef791f4cbf1","status":"affected","versionType":"git"},{"version":"e6f7e1487ab528a6c653bd0d42812ff2942846cd","lessThan":"58884694978a3d7d111edb433d7fd6a6c5af2f34","status":"affected","versionType":"git"},{"version":"986a21ace186433e0397a59491646edad8c8d636","status":"affected","versionType":"git"},{"version":"6.15.3","lessThan":"6.16","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfsd/localio.c"],"versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.16","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.16","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.16","versionEndExcluding":"7.3-rc1"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15.3"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/763c0bad872368304db718f79af7e93048885c67"},{"url":"https://git.kernel.org/stable/c/559570f91a7d4d199a72105e4980bef791f4cbf1"},{"url":"https://git.kernel.org/stable/c/58884694978a3d7d111edb433d7fd6a6c5af2f34"}],"title":"nfsd: hold rcu across localio cmpxchg retry","x_generator":{"engine":"bippy-1.2.0"}}}}