๐Ÿ” CVE Alert

CVE-2026-89707

HIGH 7.5

nfsd: release path refs on follow_down() error

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: nfsd: release path refs on follow_down() error nfsd_cross_mnt() initializes a local struct path with mntget() and dget() before calling follow_down(). On a negative return the error arm jumps to out without releasing those references: err = follow_down(&path, follow_flags); if (err < 0) goto out; follow_down() never drops the caller's entry-time refs on any error sub-case; for example a pre-cross d_manage() failure leaves path untouched, so the mntget()/dget() taken on entry survive the call. Every other early-exit arm in nfsd_cross_mnt() (other-namespace return, IS_ERR(exp2), and the success tail after the swap) already calls path_put(&path); the err < 0 arm is the lone omission. The leak inflates mnt_count and d_count on each failed cross-mount, blocking umount and pinning dentries against the shrinker, and is reachable by any authenticated NFS client through nfsd_lookup_dentry or the NFSv4 READDIR encode path. Fix by calling path_put(&path) before the goto out in the err < 0 arm so the entry-time refs are released on all follow_down() error returns.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
cc53ce53c86924bfe98a12ea20b7465038a08792 < 085cfde7c2186acaad103f02d2c25435ad5224e9 cc53ce53c86924bfe98a12ea20b7465038a08792 < 194316df81263519156ebe714c4a286bee00e5be cc53ce53c86924bfe98a12ea20b7465038a08792 < 467d56fd3ff57447a790c6dc3ede2d02a947d224 cc53ce53c86924bfe98a12ea20b7465038a08792 < 2bc4343308d85ee4e0dd3877b384306c96f114c2 cc53ce53c86924bfe98a12ea20b7465038a08792 < 6cba08dc1922140d260cfeb30bbda4ee1bf869d8
Linux / Linux
2.6.38

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/085cfde7c2186acaad103f02d2c25435ad5224e9 git.kernel.org: https://git.kernel.org/stable/c/194316df81263519156ebe714c4a286bee00e5be git.kernel.org: https://git.kernel.org/stable/c/467d56fd3ff57447a790c6dc3ede2d02a947d224 git.kernel.org: https://git.kernel.org/stable/c/2bc4343308d85ee4e0dd3877b384306c96f114c2 git.kernel.org: https://git.kernel.org/stable/c/6cba08dc1922140d260cfeb30bbda4ee1bf869d8