{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89715","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.751Z","datePublished":"2026-09-11T19:46:29.227Z","dateUpdated":"2026-09-11T19:46:29.227Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-11T19:46:29.227Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nNFS/localio: fix ref leak on nfs_uuid_add_file failure\n\nWhen nfs_uuid_add_file() races with nfs_uuid_put() tearing down\nuuid->net, it returns -ENXIO without publishing nfl->nfs_uuid via\nrcu_assign_pointer().  nfs_open_local_fh() then enters its error\nbranch and only releases the slot's file ref and its paired net\nref plus its own entry-time net ref, while the close path is a\nno-op:\n\n    nfs_close_local_fh()\n      nfs_uuid = rcu_dereference(nfl->nfs_uuid);\n      if (!nfs_uuid) { rcu_read_unlock(); return; }  /* always */\n\nnfsd_open_local_fh() returns localio holding a caller-owned +1\nnfsd_file reference (from nfsd_file_get() after\nnfsd_file_acquire_local()) and an entry-time nfsd_net reference\n(from its first nfsd_net_try_get()) embedded as nf->nf_net.  Both\nare leaked on the failure path, pinning one nfsd_file (and the\nunderlying struct file, dentry, inode) and one nfsd_net_ref per\noccurrence, which blocks nfsd_net and netns teardown.\n\nFix by releasing the caller-owned file ref and its net ref through\nthe existing helper, using a stack-local RCU pointer so the helper\ncan xchg it out, then returning -ENXIO so callers do not\ndereference a localio whose slot has been cleared:\n\n    struct nfsd_file __rcu *tmp = RCU_INITIALIZER(localio);\n\n    nfs_to_nfsd_file_put_local(pnf);\n    nfs_to_nfsd_file_put_local(&tmp);\n    localio = ERR_PTR(-ENXIO);\n\nThe trailing nfs_to_nfsd_net_put(net) continues to release the\nouter net ref, so all three nfsd_net_try_get() increments are\nbalanced on the error branch."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfs_common/nfslocalio.c"],"versions":[{"version":"fdd015de767977f21892329af5e12276eb80375f","lessThan":"5215e734bf7cba18237155f8cb2a0accb60ca339","status":"affected","versionType":"git"},{"version":"fdd015de767977f21892329af5e12276eb80375f","lessThan":"9f59b05423ed381f8cdeaaae4bd6778adcb6865c","status":"affected","versionType":"git"},{"version":"fdd015de767977f21892329af5e12276eb80375f","lessThan":"ca018c19e0ba38975e5ddc3ef8117d5b734313aa","status":"affected","versionType":"git"},{"version":"55735dc5a0ee0c0fc14cb51e005eae862906a410","status":"affected","versionType":"git"},{"version":"7cac8a129fc53497f9ee5d66fca55a245d009b97","status":"affected","versionType":"git"},{"version":"6.15.10","lessThan":"6.16","status":"affected","versionType":"semver"},{"version":"6.16.1","lessThan":"6.17","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfs_common/nfslocalio.c"],"versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.17","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.17","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.17","versionEndExcluding":"7.3-rc1"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15.10"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.16.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/5215e734bf7cba18237155f8cb2a0accb60ca339"},{"url":"https://git.kernel.org/stable/c/9f59b05423ed381f8cdeaaae4bd6778adcb6865c"},{"url":"https://git.kernel.org/stable/c/ca018c19e0ba38975e5ddc3ef8117d5b734313aa"}],"title":"NFS/localio: fix ref leak on nfs_uuid_add_file failure","x_generator":{"engine":"bippy-1.2.0"}}}}