NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check
Summary
| CVE | CVE-2026-89711 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-11 20:19:58 UTC |
| Updated | 2026-09-11 20:19:58 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check
The header for commit e75b23f9e323 ("nfsd: check d_can_lookup in
fh_verify of directories") details the assumption that justified
adding the WARN_ON_ONCE to nfsd_mode_check(), that assumption is
invalid (in the case of NFS reexport).
When NFSD exports an NFS filesystem it is very possible for
nfsd_mode_check() to encounter a @dentry that doesn't have
i_op->lookup (see nfs_fhget()'s NFS_ATTR_FATTR_MOUNTPOINT and
NFS_ATTR_FATTR_V4_REFERRAL handling, and d_flags_for_inode()).
So remove nfsd_mode_check()'s WARN_ON_ONCE(). The nfserr_notdir
return on that branch must stay. It guards the subsequent
lookup_one_unlocked() -> __lookup_slow() path, which calls
inode->i_op->lookup() with no NULL check, so returning nfserr_notdir
is what keeps a client LOOKUP into such a @dentry from dereferencing
a NULL method pointer. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c b55b4d880bb080fa10eb08ba21a5d8679b8102fe git |
Not specified |
| CNA |
Linux |
Linux |
affected e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c 7ef182a8fe9c12b0d936880b1e504840639aa009 git |
Not specified |
| CNA |
Linux |
Linux |
affected e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c a275de3bac5635514ca830f2e46b5ff0e66b5c4c git |
Not specified |
| CNA |
Linux |
Linux |
affected e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c aa0cf48a448c5a9fe1a1e880899ecd589ce39e6e git |
Not specified |
| CNA |
Linux |
Linux |
affected 4.8 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 4.8 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.109 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.50 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2.4 7.2.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.3-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/a275de3bac5635514ca830f2e46b5ff0e66b5c4c |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/aa0cf48a448c5a9fe1a1e880899ecd589ce39e6e |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/b55b4d880bb080fa10eb08ba21a5d8679b8102fe |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/7ef182a8fe9c12b0d936880b1e504840639aa009 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.