{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89696","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.750Z","datePublished":"2026-09-11T19:46:15.030Z","dateUpdated":"2026-09-14T12:02:03.192Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:02:03.192Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref\n\nWhen CONFIG_NFSD_V4_2_INTER_SSC is enabled, nfsd4_putfh() can return\nsuccess with fh_dentry and fh_export both NULL if fh_verify() returns\nnfserr_stale and putfh->no_verify is true. The NFSD4_FH_FOREIGN flag\nis set, but the compound dispatch loop only uses this flag to bypass\nthe nfserr_nofilehandle check -- it does not prevent subsequent ops\nfrom running with a NULL fh_dentry.\n\nA remote client can exploit this by crafting a COMPOUND that includes\nan inter-SSC COPY (which causes check_if_stalefh_allowed() to set\nno_verify=true on the saved PUTFH) with an additional op inserted\nbetween the source PUTFH and SAVEFH. For example, SETATTR calls\nfh_want_write() which dereferences fh_export->ex_path.mnt without\ncalling fh_verify() first, causing a NULL pointer dereference in the\nnfsd kthread.\n\nFix this by gating the dispatch loop: when NFSD4_FH_FOREIGN is set\nand fh_dentry is NULL, only OP_SAVEFH (needed for the inter-SSC flow)\nand ops with ALLOWED_WITHOUT_FH (which don't need a resolved\nfilehandle) may proceed. All other ops receive nfserr_stale, per\nRFC 7862 Section 15.2.3 which specifies that foreign filehandle\nvalidation is deferred to the consuming operation and NFS4ERR_STALE\nreturned at that point."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - The bug is in nfsd NFSv4 COMPOUND dispatch and is triggered by a crafted NFSv4.2 COMPOUND over TCP/2049 (PUTFH of a stale fh, then SETATTR, with an inter-SSC COPY in the same compound). No local access is required.\nAC:L - After EXCHANGE_ID/CREATE_SESSION, the attacker fully controls the compound that marks the source PUTFH no_verify and inserts SETATTR before SAVEFH, so fh_want_write hits NULL fh_export deterministically with no race or layout dependency.\nPR:N - AUTH_SYS (the usual nfsd configuration) verifies no secret; a client just asserts a UID to create a session. SETATTR then runs on the FOREIGN fh without fh_verify, so no export access check or other credential gate is reached.\nUI:N - The attacker sends the COMPOUND directly to nfsd; no administrator or victim user action is required at exploitation time.\nS:U - The NULL dereference oopses the nfsd kthread in the host kernel's own authority and does not cross a VM, IOMMU, or sandbox boundary.\nC:N - After the stale FOREIGN PUTFH, fh_export and fh_dentry are NULL rather than dangling or attacker-controlled, so the fault is on the first load of fh_export->ex_path.mnt with no disclosure.\nI:N - This is a pure NULL pointer dereference in fh_want_write with no write to attacker-influenced memory and no control-flow hijack primitive.\nA:H - The NULL dereference oopses the nfsd kthread and can be replayed to exhaust nfsd threads, denying NFS service; with panic_on_oops it panics the host."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfsd/nfs4proc.c"],"versions":[{"version":"b9e8638e3d9ed8334f1f7071e081860aac37e83e","lessThan":"ffdc844e673d2bcb2af8c8c3eef8cdea59d0bf32","status":"affected","versionType":"git"},{"version":"b9e8638e3d9ed8334f1f7071e081860aac37e83e","lessThan":"00c84f4eec715e501efc080a5670114189e42507","status":"affected","versionType":"git"},{"version":"b9e8638e3d9ed8334f1f7071e081860aac37e83e","lessThan":"2d9846fd1c767920fddd4bde30eb35cd2969df13","status":"affected","versionType":"git"},{"version":"b9e8638e3d9ed8334f1f7071e081860aac37e83e","lessThan":"977e6f006a7a3ffc4216ae6034f768f8de6fd138","status":"affected","versionType":"git"},{"version":"b9e8638e3d9ed8334f1f7071e081860aac37e83e","lessThan":"35f248bd40b47b229d4999581df45b97daadd977","status":"affected","versionType":"git"},{"version":"b9e8638e3d9ed8334f1f7071e081860aac37e83e","lessThan":"311f7d926630940650447cbd1c932b076b40a6c4","status":"affected","versionType":"git"},{"version":"b9e8638e3d9ed8334f1f7071e081860aac37e83e","lessThan":"bf4d338dc8625d70c7f2cb0657d66851a7ac9154","status":"affected","versionType":"git"},{"version":"b9e8638e3d9ed8334f1f7071e081860aac37e83e","lessThan":"c59738a00aa51b16adc1b5ceb7c80877168efb4d","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfsd/nfs4proc.c"],"versions":[{"version":"5.6","status":"affected"},{"version":"0","lessThan":"5.6","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/ffdc844e673d2bcb2af8c8c3eef8cdea59d0bf32"},{"url":"https://git.kernel.org/stable/c/00c84f4eec715e501efc080a5670114189e42507"},{"url":"https://git.kernel.org/stable/c/2d9846fd1c767920fddd4bde30eb35cd2969df13"},{"url":"https://git.kernel.org/stable/c/977e6f006a7a3ffc4216ae6034f768f8de6fd138"},{"url":"https://git.kernel.org/stable/c/35f248bd40b47b229d4999581df45b97daadd977"},{"url":"https://git.kernel.org/stable/c/311f7d926630940650447cbd1c932b076b40a6c4"},{"url":"https://git.kernel.org/stable/c/bf4d338dc8625d70c7f2cb0657d66851a7ac9154"},{"url":"https://git.kernel.org/stable/c/c59738a00aa51b16adc1b5ceb7c80877168efb4d"}],"title":"nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref","x_generator":{"engine":"bippy-1.2.0"}}}}