nfsd: release path refs on follow_down() error
Summary
| CVE | CVE-2026-89707 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-11 20:19:58 UTC |
| Updated | 2026-09-11 20:19:58 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
nfsd: release path refs on follow_down() error
nfsd_cross_mnt() initializes a local struct path with mntget() and
dget() before calling follow_down(). On a negative return the error
arm jumps to out without releasing those references:
err = follow_down(&path, follow_flags);
if (err < 0)
goto out;
follow_down() never drops the caller's entry-time refs on any error
sub-case; for example a pre-cross d_manage() failure leaves path
untouched, so the mntget()/dget() taken on entry survive the call.
Every other early-exit arm in nfsd_cross_mnt() (other-namespace
return, IS_ERR(exp2), and the success tail after the swap) already
calls path_put(&path); the err < 0 arm is the lone omission. The
leak inflates mnt_count and d_count on each failed cross-mount,
blocking umount and pinning dentries against the shrinker, and is
reachable by any authenticated NFS client through nfsd_lookup_dentry
or the NFSv4 READDIR encode path.
Fix by calling path_put(&path) before the goto out in the err < 0
arm so the entry-time refs are released on all follow_down() error
returns. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected cc53ce53c86924bfe98a12ea20b7465038a08792 194316df81263519156ebe714c4a286bee00e5be git |
Not specified |
| CNA |
Linux |
Linux |
affected cc53ce53c86924bfe98a12ea20b7465038a08792 467d56fd3ff57447a790c6dc3ede2d02a947d224 git |
Not specified |
| CNA |
Linux |
Linux |
affected cc53ce53c86924bfe98a12ea20b7465038a08792 2bc4343308d85ee4e0dd3877b384306c96f114c2 git |
Not specified |
| CNA |
Linux |
Linux |
affected cc53ce53c86924bfe98a12ea20b7465038a08792 6cba08dc1922140d260cfeb30bbda4ee1bf869d8 git |
Not specified |
| CNA |
Linux |
Linux |
affected 2.6.38 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 2.6.38 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.109 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.50 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2.4 7.2.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.3-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/194316df81263519156ebe714c4a286bee00e5be |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/467d56fd3ff57447a790c6dc3ede2d02a947d224 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/6cba08dc1922140d260cfeb30bbda4ee1bf869d8 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/2bc4343308d85ee4e0dd3877b384306c96f114c2 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.