{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89680","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.748Z","datePublished":"2026-09-11T19:46:03.468Z","dateUpdated":"2026-09-13T06:33:03.627Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:33:03.627Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: fix nfsd_file leak on inter-server COPY setup failure\n\nWhen nfsd4_setup_inter_ssc() fails, nfsd4_copy() returns\nnfserr_offload_denied directly, bypassing the out: label where\nrelease_copy_files() would drop the nf_dst reference taken by\nnfs4_preprocess_stateid_op(). Each failed inter-server COPY\nleaks one nfsd_file, pinning file/inode/dentry/vfsmount.\n\nFix by setting status and jumping to out: instead of returning\ndirectly."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - nfsd's NFSv4.2 OP_COPY is reached over TCP/2049: svc_recv to nfsd_dispatch to nfsd4_proc_compound to nfsd4_copy to nfsd4_setup_inter_ssc. A remote client triggers the leak with a COMPOUND; no local access to the server is required.\nAC:L - Once inter-server COPY offload is enabled, the attacker controls every trigger: async COPY on the wire, a valid dest write stateid, and a source nl4_server that makes nfsd4_interssc_connect fail (bad uaddr/netid or failed mount). No race or attacker-uncontrollable layout is required.\nPR:N - Under default AUTH_SYS, EXCHANGE_ID/CREATE_SESSION and OPEN verify no secret; a remote client permitted by the export asserts a UID and obtains write stateids. This matches PR:N on the same nfsd4_copy path (CVE-2024-53073, CVE-2024-50241).\nUI:N - The attacker's own NFSv4.2 COMPOUND traffic drives nfsd4_copy; no administrator or local user on the server must mount, open a file, or otherwise interact beyond nfsd already serving an export.\nS:U - The leaked nfsd_file reference pins file/inode/dentry/vfsmount inside the NFS server kernel's own security authority; there is no VM, IOMMU, or sandbox boundary crossing.\nC:N - The defect only skips nfsd_file_put() on an extra filecache reference taken by nfs4_preprocess_stateid_op(); there is no out-of-bounds read, use-after-free, or other disclosure of kernel memory to the client.\nI:N - COPY setup fails before nfsd_copy_range, so no file data is modified; the leaked reference is not attacker-controlled reused memory and yields no write or control-flow primitive.\nA:H - Each failed inter-server COPY permanently leaks one nfsd_file ref, pinning the dest file/inode/dentry/vfsmount. Repeating against many created-then-unlinked files unbounded-pins slab and inodes and blocks umount, enabling remote kernel memory exhaustion and NFS server DoS."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfsd/nfs4proc.c"],"versions":[{"version":"ce0887ac96d35c7105090e166bb0807dc0a0e838","lessThan":"1a6a41b848455bf6ba2c9da2dfb0730e608ce7ab","status":"affected","versionType":"git"},{"version":"ce0887ac96d35c7105090e166bb0807dc0a0e838","lessThan":"424d5c95108a4809b832cb0a312c61de4aec0078","status":"affected","versionType":"git"},{"version":"ce0887ac96d35c7105090e166bb0807dc0a0e838","lessThan":"6ed8d6de7ec90c4ba84eb82673058f506e5777fd","status":"affected","versionType":"git"},{"version":"ce0887ac96d35c7105090e166bb0807dc0a0e838","lessThan":"88a76145451d703eedd867b5989bf73d17340399","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfsd/nfs4proc.c"],"versions":[{"version":"5.6","status":"affected"},{"version":"0","lessThan":"5.6","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/1a6a41b848455bf6ba2c9da2dfb0730e608ce7ab"},{"url":"https://git.kernel.org/stable/c/424d5c95108a4809b832cb0a312c61de4aec0078"},{"url":"https://git.kernel.org/stable/c/6ed8d6de7ec90c4ba84eb82673058f506e5777fd"},{"url":"https://git.kernel.org/stable/c/88a76145451d703eedd867b5989bf73d17340399"}],"title":"nfsd: fix nfsd_file leak on inter-server COPY setup failure","x_generator":{"engine":"bippy-1.2.0"}}}}