{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89687","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.749Z","datePublished":"2026-09-11T19:46:08.630Z","dateUpdated":"2026-09-13T06:33:11.048Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:33:11.048Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: ensure nfsd_file_do_acquire() does not use a non-opened file\n\n->atomic_open is permitted to return success without actually opening\nthe file.  It indicates this by calling finish_no_open().\nThis means dentry_create() can return a file which hasn't been opened.\nThis is extremely unlikely as ->atomic_open handlers typically\nuse finish_no_open() only for already existing files, and dentry_create()\nisn't called in that case, and the parent being locked should prevent\nraces.\n\nHowever out of an abundance of caution it seems wise to teach nfsd to\nonly use the file returned by dentry_create() if FMODE_OPENED is set,\nindicating that it has in fact been opened."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - nfsd is a network NFS server. The bug is in the NFSv4 OPEN+CREATE path (nfsd4_vfs_create → dentry_create → nfsd_file_acquire_opened), reached by a remote client sending COMPOUND operations over TCP/2049.\nAC:L - Filesystems whose ->atomic_open creates then calls finish_no_open (notably FUSE when FUSE_CREATE is unimplemented) reliably return an unopened struct file; the attacker only sends a normal OPEN with CREATE and does not depend on an uncontrolled race.\nPR:N - Default nfsd deployments accept AUTH_SYS, which does not cryptographically authenticate the peer. An unauthenticated network attacker who can reach a writable export can spoof a UID and issue OPEN+CREATE with no credentials.\nUI:N - Exploitation uses only attacker-sent NFSv4 requests (clientid/session setup, PUTFH, OPEN with CREATE). No victim action such as mounting a filesystem or opening a file is required.\nS:U - Impact is a kernel oops in the nfsd worker on the host. That is denial of service within the same kernel security authority, not a VM, IOMMU, or sandbox escape.\nC:N - The unused file is allocated via alloc_empty_file with f_op, f_mapping, and f_inode set to NULL. Later use is a NULL-pointer dereference that oopses and does not provide a read primitive or information disclosure.\nI:N - This is not a use-after-free, OOB write, or type confusion; the struct file is valid but never opened, so f_op stays NULL. There is no write primitive or control-flow hijack, only a crash.\nA:H - Caching the unopened file NULL-dereferences f_mapping in nfsd_file_check_write_error on write opens, or f_op on later READ/WRITE/close (vfs_iocb_iter_read, filp_flush), oopsing the nfsd thread and denying NFS service."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfsd/filecache.c"],"versions":[{"version":"64a989dbd144e0622371396461b11335459692d2","lessThan":"a95a1cffacd0203100297001719160160f443dd6","status":"affected","versionType":"git"},{"version":"64a989dbd144e0622371396461b11335459692d2","lessThan":"5859cc01fee06a2cd7458905a9593082fbab06e1","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfsd/filecache.c"],"versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/a95a1cffacd0203100297001719160160f443dd6"},{"url":"https://git.kernel.org/stable/c/5859cc01fee06a2cd7458905a9593082fbab06e1"}],"title":"nfsd: ensure nfsd_file_do_acquire() does not use a non-opened file","x_generator":{"engine":"bippy-1.2.0"}}}}