{"api_version":"1","generated_at":"2026-09-12T11:59:10+00:00","cve":"CVE-2026-89715","urls":{"html":"https://cve.report/CVE-2026-89715","api":"https://cve.report/api/cve/CVE-2026-89715.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-89715","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-89715"},"summary":{"title":"NFS/localio: fix ref leak on nfs_uuid_add_file failure","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nNFS/localio: fix ref leak on nfs_uuid_add_file failure\n\nWhen nfs_uuid_add_file() races with nfs_uuid_put() tearing down\nuuid->net, it returns -ENXIO without publishing nfl->nfs_uuid via\nrcu_assign_pointer().  nfs_open_local_fh() then enters its error\nbranch and only releases the slot's file ref and its paired net\nref plus its own entry-time net ref, while the close path is a\nno-op:\n\n    nfs_close_local_fh()\n      nfs_uuid = rcu_dereference(nfl->nfs_uuid);\n      if (!nfs_uuid) { rcu_read_unlock(); return; }  /* always */\n\nnfsd_open_local_fh() returns localio holding a caller-owned +1\nnfsd_file reference (from nfsd_file_get() after\nnfsd_file_acquire_local()) and an entry-time nfsd_net reference\n(from its first nfsd_net_try_get()) embedded as nf->nf_net.  Both\nare leaked on the failure path, pinning one nfsd_file (and the\nunderlying struct file, dentry, inode) and one nfsd_net_ref per\noccurrence, which blocks nfsd_net and netns teardown.\n\nFix by releasing the caller-owned file ref and its net ref through\nthe existing helper, using a stack-local RCU pointer so the helper\ncan xchg it out, then returning -ENXIO so callers do not\ndereference a localio whose slot has been cleared:\n\n    struct nfsd_file __rcu *tmp = RCU_INITIALIZER(localio);\n\n    nfs_to_nfsd_file_put_local(pnf);\n    nfs_to_nfsd_file_put_local(&tmp);\n    localio = ERR_PTR(-ENXIO);\n\nThe trailing nfs_to_nfsd_net_put(net) continues to release the\nouter net ref, so all three nfsd_net_try_get() increments are\nbalanced on the error branch.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-11 20:19:58","updated_at":"2026-09-11 20:19:58"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/5215e734bf7cba18237155f8cb2a0accb60ca339","name":"https://git.kernel.org/stable/c/5215e734bf7cba18237155f8cb2a0accb60ca339","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/ca018c19e0ba38975e5ddc3ef8117d5b734313aa","name":"https://git.kernel.org/stable/c/ca018c19e0ba38975e5ddc3ef8117d5b734313aa","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/9f59b05423ed381f8cdeaaae4bd6778adcb6865c","name":"https://git.kernel.org/stable/c/9f59b05423ed381f8cdeaaae4bd6778adcb6865c","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89715","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89715","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected fdd015de767977f21892329af5e12276eb80375f 5215e734bf7cba18237155f8cb2a0accb60ca339 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected fdd015de767977f21892329af5e12276eb80375f 9f59b05423ed381f8cdeaaae4bd6778adcb6865c git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected fdd015de767977f21892329af5e12276eb80375f ca018c19e0ba38975e5ddc3ef8117d5b734313aa git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 55735dc5a0ee0c0fc14cb51e005eae862906a410 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7cac8a129fc53497f9ee5d66fca55a245d009b97 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.15.10 6.16 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.16.1 6.17 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.17","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.17 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.50 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.4 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["fs/nfs_common/nfslocalio.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"5215e734bf7cba18237155f8cb2a0accb60ca339","status":"affected","version":"fdd015de767977f21892329af5e12276eb80375f","versionType":"git"},{"lessThan":"9f59b05423ed381f8cdeaaae4bd6778adcb6865c","status":"affected","version":"fdd015de767977f21892329af5e12276eb80375f","versionType":"git"},{"lessThan":"ca018c19e0ba38975e5ddc3ef8117d5b734313aa","status":"affected","version":"fdd015de767977f21892329af5e12276eb80375f","versionType":"git"},{"status":"affected","version":"55735dc5a0ee0c0fc14cb51e005eae862906a410","versionType":"git"},{"status":"affected","version":"7cac8a129fc53497f9ee5d66fca55a245d009b97","versionType":"git"},{"lessThan":"6.16","status":"affected","version":"6.15.10","versionType":"semver"},{"lessThan":"6.17","status":"affected","version":"6.16.1","versionType":"semver"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["fs/nfs_common/nfslocalio.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.17"},{"lessThan":"6.17","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.50","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.4","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.50","versionStartIncluding":"6.17","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.4","versionStartIncluding":"6.17","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"6.17","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15.10","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.16.1","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nNFS/localio: fix ref leak on nfs_uuid_add_file failure\n\nWhen nfs_uuid_add_file() races with nfs_uuid_put() tearing down\nuuid->net, it returns -ENXIO without publishing nfl->nfs_uuid via\nrcu_assign_pointer().  nfs_open_local_fh() then enters its error\nbranch and only releases the slot's file ref and its paired net\nref plus its own entry-time net ref, while the close path is a\nno-op:\n\n    nfs_close_local_fh()\n      nfs_uuid = rcu_dereference(nfl->nfs_uuid);\n      if (!nfs_uuid) { rcu_read_unlock(); return; }  /* always */\n\nnfsd_open_local_fh() returns localio holding a caller-owned +1\nnfsd_file reference (from nfsd_file_get() after\nnfsd_file_acquire_local()) and an entry-time nfsd_net reference\n(from its first nfsd_net_try_get()) embedded as nf->nf_net.  Both\nare leaked on the failure path, pinning one nfsd_file (and the\nunderlying struct file, dentry, inode) and one nfsd_net_ref per\noccurrence, which blocks nfsd_net and netns teardown.\n\nFix by releasing the caller-owned file ref and its net ref through\nthe existing helper, using a stack-local RCU pointer so the helper\ncan xchg it out, then returning -ENXIO so callers do not\ndereference a localio whose slot has been cleared:\n\n    struct nfsd_file __rcu *tmp = RCU_INITIALIZER(localio);\n\n    nfs_to_nfsd_file_put_local(pnf);\n    nfs_to_nfsd_file_put_local(&tmp);\n    localio = ERR_PTR(-ENXIO);\n\nThe trailing nfs_to_nfsd_net_put(net) continues to release the\nouter net ref, so all three nfsd_net_try_get() increments are\nbalanced on the error branch."}],"providerMetadata":{"dateUpdated":"2026-09-11T19:46:29.227Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/5215e734bf7cba18237155f8cb2a0accb60ca339"},{"url":"https://git.kernel.org/stable/c/9f59b05423ed381f8cdeaaae4bd6778adcb6865c"},{"url":"https://git.kernel.org/stable/c/ca018c19e0ba38975e5ddc3ef8117d5b734313aa"}],"title":"NFS/localio: fix ref leak on nfs_uuid_add_file failure","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-89715","datePublished":"2026-09-11T19:46:29.227Z","dateReserved":"2026-09-11T19:38:34.751Z","dateUpdated":"2026-09-11T19:46:29.227Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-11 20:19:58","lastModifiedDate":"2026-09-11 20:19:58","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"89715","Ordinal":"1","Title":"NFS/localio: fix ref leak on nfs_uuid_add_file failure","CVE":"CVE-2026-89715","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"89715","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nNFS/localio: fix ref leak on nfs_uuid_add_file failure\n\nWhen nfs_uuid_add_file() races with nfs_uuid_put() tearing down\nuuid->net, it returns -ENXIO without publishing nfl->nfs_uuid via\nrcu_assign_pointer().  nfs_open_local_fh() then enters its error\nbranch and only releases the slot's file ref and its paired net\nref plus its own entry-time net ref, while the close path is a\nno-op:\n\n    nfs_close_local_fh()\n      nfs_uuid = rcu_dereference(nfl->nfs_uuid);\n      if (!nfs_uuid) { rcu_read_unlock(); return; }  /* always */\n\nnfsd_open_local_fh() returns localio holding a caller-owned +1\nnfsd_file reference (from nfsd_file_get() after\nnfsd_file_acquire_local()) and an entry-time nfsd_net reference\n(from its first nfsd_net_try_get()) embedded as nf->nf_net.  Both\nare leaked on the failure path, pinning one nfsd_file (and the\nunderlying struct file, dentry, inode) and one nfsd_net_ref per\noccurrence, which blocks nfsd_net and netns teardown.\n\nFix by releasing the caller-owned file ref and its net ref through\nthe existing helper, using a stack-local RCU pointer so the helper\ncan xchg it out, then returning -ENXIO so callers do not\ndereference a localio whose slot has been cleared:\n\n    struct nfsd_file __rcu *tmp = RCU_INITIALIZER(localio);\n\n    nfs_to_nfsd_file_put_local(pnf);\n    nfs_to_nfsd_file_put_local(&tmp);\n    localio = ERR_PTR(-ENXIO);\n\nThe trailing nfs_to_nfsd_net_put(net) continues to release the\nouter net ref, so all three nfsd_net_try_get() increments are\nbalanced on the error branch.","Type":"Description","Title":"NFS/localio: fix ref leak on nfs_uuid_add_file failure"}]}}}