๐Ÿ” CVE Alert

CVE-2026-89696

HIGH 7.5

nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref When CONFIG_NFSD_V4_2_INTER_SSC is enabled, nfsd4_putfh() can return success with fh_dentry and fh_export both NULL if fh_verify() returns nfserr_stale and putfh->no_verify is true. The NFSD4_FH_FOREIGN flag is set, but the compound dispatch loop only uses this flag to bypass the nfserr_nofilehandle check -- it does not prevent subsequent ops from running with a NULL fh_dentry. A remote client can exploit this by crafting a COMPOUND that includes an inter-SSC COPY (which causes check_if_stalefh_allowed() to set no_verify=true on the saved PUTFH) with an additional op inserted between the source PUTFH and SAVEFH. For example, SETATTR calls fh_want_write() which dereferences fh_export->ex_path.mnt without calling fh_verify() first, causing a NULL pointer dereference in the nfsd kthread. Fix this by gating the dispatch loop: when NFSD4_FH_FOREIGN is set and fh_dentry is NULL, only OP_SAVEFH (needed for the inter-SSC flow) and ops with ALLOWED_WITHOUT_FH (which don't need a resolved filehandle) may proceed. All other ops receive nfserr_stale, per RFC 7862 Section 15.2.3 which specifies that foreign filehandle validation is deferred to the consuming operation and NFS4ERR_STALE returned at that point.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
b9e8638e3d9ed8334f1f7071e081860aac37e83e < ffdc844e673d2bcb2af8c8c3eef8cdea59d0bf32 b9e8638e3d9ed8334f1f7071e081860aac37e83e < 00c84f4eec715e501efc080a5670114189e42507 b9e8638e3d9ed8334f1f7071e081860aac37e83e < 2d9846fd1c767920fddd4bde30eb35cd2969df13 b9e8638e3d9ed8334f1f7071e081860aac37e83e < 977e6f006a7a3ffc4216ae6034f768f8de6fd138 b9e8638e3d9ed8334f1f7071e081860aac37e83e < 35f248bd40b47b229d4999581df45b97daadd977 b9e8638e3d9ed8334f1f7071e081860aac37e83e < 311f7d926630940650447cbd1c932b076b40a6c4 b9e8638e3d9ed8334f1f7071e081860aac37e83e < bf4d338dc8625d70c7f2cb0657d66851a7ac9154 b9e8638e3d9ed8334f1f7071e081860aac37e83e < c59738a00aa51b16adc1b5ceb7c80877168efb4d
Linux / Linux
5.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/ffdc844e673d2bcb2af8c8c3eef8cdea59d0bf32 git.kernel.org: https://git.kernel.org/stable/c/00c84f4eec715e501efc080a5670114189e42507 git.kernel.org: https://git.kernel.org/stable/c/2d9846fd1c767920fddd4bde30eb35cd2969df13 git.kernel.org: https://git.kernel.org/stable/c/977e6f006a7a3ffc4216ae6034f768f8de6fd138 git.kernel.org: https://git.kernel.org/stable/c/35f248bd40b47b229d4999581df45b97daadd977 git.kernel.org: https://git.kernel.org/stable/c/311f7d926630940650447cbd1c932b076b40a6c4 git.kernel.org: https://git.kernel.org/stable/c/bf4d338dc8625d70c7f2cb0657d66851a7ac9154 git.kernel.org: https://git.kernel.org/stable/c/c59738a00aa51b16adc1b5ceb7c80877168efb4d