{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89707","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.751Z","datePublished":"2026-09-11T19:46:23.293Z","dateUpdated":"2026-09-14T12:02:08.548Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:02:08.548Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: release path refs on follow_down() error\n\nnfsd_cross_mnt() initializes a local struct path with mntget() and\ndget() before calling follow_down(). On a negative return the error\narm jumps to out without releasing those references:\n\n    err = follow_down(&path, follow_flags);\n    if (err < 0)\n            goto out;\n\nfollow_down() never drops the caller's entry-time refs on any error\nsub-case; for example a pre-cross d_manage() failure leaves path\nuntouched, so the mntget()/dget() taken on entry survive the call.\n\nEvery other early-exit arm in nfsd_cross_mnt() (other-namespace\nreturn, IS_ERR(exp2), and the success tail after the swap) already\ncalls path_put(&path); the err < 0 arm is the lone omission. The\nleak inflates mnt_count and d_count on each failed cross-mount,\nblocking umount and pinning dentries against the shrinker, and is\nreachable by any authenticated NFS client through nfsd_lookup_dentry\nor the NFSv4 READDIR encode path.\n\nFix by calling path_put(&path) before the goto out in the err < 0\narm so the entry-time refs are released on all follow_down() error\nreturns."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - nfsd_cross_mnt() runs in the in-kernel NFS server on TCP/UDP 2049 from nfsd_lookup_dentry() (NFSv2/v3/v4 LOOKUP) and nfsd4_encode_entry4_fattr() (NFSv4 READDIR); a remote client reaches it with ordinary RPC requests.\nAC:L - On a typical nfsd export of autofs homes or nested mounts with crossmnt, an attacker can deterministically make follow_down() fail (autofs d_manage/automount error) by repeating LOOKUP/READDIR of failing mount triggers; no race or victim-controlled layout is required.\nPR:N - Default nfsd exports accept RPC_AUTH_NULL and RPC_AUTH_UNIX with no password; fh_verify only checks export IP policy, a MOUNT/PUTROOTFH filehandle, and directory execute, so no Linux account or capability on the server is required.\nUI:N - The attacker triggers the leak with their own NFS LOOKUP or READDIR RPCs; no victim mount, click, or other interactive action is required.\nS:U - The leak inflates dentry and vfsmount refcounts inside the nfsd host kernel and does not cross a VM, IOMMU, or other separate security authority.\nC:N - The bug only fails to path_put() the mntget/dget taken before follow_down(); it does not read kernel or file data or provide an information-disclosure primitive.\nI:N - The bug does not write attacker-controlled data or corrupt kernel objects; it only retains extra references on existing dentries and mounts.\nA:H - Each failed follow_down() permanently pins the dentry and vfsmount; repeated LOOKUPs of distinct autofs/mountpoint names leave unreclaimable dentries, block umount, and can exhaust kernel memory for a system-wide DoS."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfsd/vfs.c"],"versions":[{"version":"cc53ce53c86924bfe98a12ea20b7465038a08792","lessThan":"085cfde7c2186acaad103f02d2c25435ad5224e9","status":"affected","versionType":"git"},{"version":"cc53ce53c86924bfe98a12ea20b7465038a08792","lessThan":"194316df81263519156ebe714c4a286bee00e5be","status":"affected","versionType":"git"},{"version":"cc53ce53c86924bfe98a12ea20b7465038a08792","lessThan":"467d56fd3ff57447a790c6dc3ede2d02a947d224","status":"affected","versionType":"git"},{"version":"cc53ce53c86924bfe98a12ea20b7465038a08792","lessThan":"2bc4343308d85ee4e0dd3877b384306c96f114c2","status":"affected","versionType":"git"},{"version":"cc53ce53c86924bfe98a12ea20b7465038a08792","lessThan":"6cba08dc1922140d260cfeb30bbda4ee1bf869d8","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfsd/vfs.c"],"versions":[{"version":"2.6.38","status":"affected"},{"version":"0","lessThan":"2.6.38","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.38","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.38","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.38","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.38","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.38","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/085cfde7c2186acaad103f02d2c25435ad5224e9"},{"url":"https://git.kernel.org/stable/c/194316df81263519156ebe714c4a286bee00e5be"},{"url":"https://git.kernel.org/stable/c/467d56fd3ff57447a790c6dc3ede2d02a947d224"},{"url":"https://git.kernel.org/stable/c/2bc4343308d85ee4e0dd3877b384306c96f114c2"},{"url":"https://git.kernel.org/stable/c/6cba08dc1922140d260cfeb30bbda4ee1bf869d8"}],"title":"nfsd: release path refs on follow_down() error","x_generator":{"engine":"bippy-1.2.0"}}}}