{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89711","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.751Z","datePublished":"2026-09-11T19:46:26.269Z","dateUpdated":"2026-09-14T12:02:10.683Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:02:10.683Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check\n\nThe header for commit e75b23f9e323 (\"nfsd: check d_can_lookup in\nfh_verify of directories\") details the assumption that justified\nadding the WARN_ON_ONCE to nfsd_mode_check(), that assumption is\ninvalid (in the case of NFS reexport).\n\nWhen NFSD exports an NFS filesystem it is very possible for\nnfsd_mode_check() to encounter a @dentry that doesn't have\ni_op->lookup (see nfs_fhget()'s NFS_ATTR_FATTR_MOUNTPOINT and\nNFS_ATTR_FATTR_V4_REFERRAL handling, and d_flags_for_inode()).\n\nSo remove nfsd_mode_check()'s WARN_ON_ONCE(). The nfserr_notdir\nreturn on that branch must stay. It guards the subsequent\nlookup_one_unlocked() -> __lookup_slow() path, which calls\ninode->i_op->lookup() with no NULL check, so returning nfserr_notdir\nis what keeps a client LOOKUP into such a @dentry from dereferencing\na NULL method pointer."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","baseScore":8.2,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - nfsd is the in-kernel NFS server. A remote client reaches nfsd_mode_check() via directory ops (LOOKUP, CREATE, OPEN) over TCP/UDP 2049: svc_recv to nfsd_dispatch to fh_verify to __fh_verify.\nAC:L - On an nfsd host that reexports NFS, mountpoint and NFSv4 referral dentries lack i_op->lookup so d_can_lookup() is false. A client LOOKUP or other S_IFDIR fh_verify on that filehandle hits WARN_ON_ONCE deterministically with no race.\nPR:N - nfsd_mode_check() runs in __fh_verify() after filehandle decode but before check_security_flavor() and nfsd_permission(). Typical nfsd deployments accept AUTH_SYS/AUTH_NULL, so an unauthenticated peer that can reach the export triggers it with self-asserted credentials.\nUI:N - The attacker sends the NFS RPCs (NFSv4 PUTFH plus LOOKUP, or NFSv3 LOOKUP) themselves. No victim user must mount a filesystem, open a file, or otherwise interact.\nS:U - The WARN_ON_ONCE splat and any panic_on_warn crash remain inside the NFS server kernel. This is not a VM escape, IOMMU bypass, or sandbox boundary crossing.\nC:L - WARN_ON_ONCE calls __warn()/dump_stack(), disclosing kernel text addresses in dmesg. There is no use-after-free or out-of-bounds read; the path returns nfserr_notdir without copying kernel memory to the client.\nI:N - The fix only removes the warning. The existing nfserr_notdir return already blocks lookup_one_unlocked() from calling a NULL i_op->lookup, so there is no memory corruption, write primitive, or control-flow hijack.\nA:H - WARN_ON_ONCE taints the kernel and panics the host when panic_on_warn is enabled or warn_limit is exceeded, so a remote NFS client can deny service by operating on a reexported mountpoint or referral directory."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfsd/nfsfh.c"],"versions":[{"version":"e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c","lessThan":"ae251937c6f0237e5b555a5e4ba4595b8206e865","status":"affected","versionType":"git"},{"version":"e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c","lessThan":"e145e8d67a5d41c72d322e7f87ab474d39d9dfb7","status":"affected","versionType":"git"},{"version":"e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c","lessThan":"9f4434893a2783f7384d993cea883aff3fb7a52d","status":"affected","versionType":"git"},{"version":"e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c","lessThan":"2ef131323999539038e306773c8256403834361b","status":"affected","versionType":"git"},{"version":"e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c","lessThan":"b55b4d880bb080fa10eb08ba21a5d8679b8102fe","status":"affected","versionType":"git"},{"version":"e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c","lessThan":"7ef182a8fe9c12b0d936880b1e504840639aa009","status":"affected","versionType":"git"},{"version":"e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c","lessThan":"a275de3bac5635514ca830f2e46b5ff0e66b5c4c","status":"affected","versionType":"git"},{"version":"e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c","lessThan":"aa0cf48a448c5a9fe1a1e880899ecd589ce39e6e","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfsd/nfsfh.c"],"versions":[{"version":"4.8","status":"affected"},{"version":"0","lessThan":"4.8","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/ae251937c6f0237e5b555a5e4ba4595b8206e865"},{"url":"https://git.kernel.org/stable/c/e145e8d67a5d41c72d322e7f87ab474d39d9dfb7"},{"url":"https://git.kernel.org/stable/c/9f4434893a2783f7384d993cea883aff3fb7a52d"},{"url":"https://git.kernel.org/stable/c/2ef131323999539038e306773c8256403834361b"},{"url":"https://git.kernel.org/stable/c/b55b4d880bb080fa10eb08ba21a5d8679b8102fe"},{"url":"https://git.kernel.org/stable/c/7ef182a8fe9c12b0d936880b1e504840639aa009"},{"url":"https://git.kernel.org/stable/c/a275de3bac5635514ca830f2e46b5ff0e66b5c4c"},{"url":"https://git.kernel.org/stable/c/aa0cf48a448c5a9fe1a1e880899ecd589ce39e6e"}],"title":"NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check","x_generator":{"engine":"bippy-1.2.0"}}}}