๐Ÿ” CVE Alert

CVE-2026-89715

UNKNOWN 0.0

NFS/localio: fix ref leak on nfs_uuid_add_file failure

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: NFS/localio: fix ref leak on nfs_uuid_add_file failure When nfs_uuid_add_file() races with nfs_uuid_put() tearing down uuid->net, it returns -ENXIO without publishing nfl->nfs_uuid via rcu_assign_pointer(). nfs_open_local_fh() then enters its error branch and only releases the slot's file ref and its paired net ref plus its own entry-time net ref, while the close path is a no-op: nfs_close_local_fh() nfs_uuid = rcu_dereference(nfl->nfs_uuid); if (!nfs_uuid) { rcu_read_unlock(); return; } /* always */ nfsd_open_local_fh() returns localio holding a caller-owned +1 nfsd_file reference (from nfsd_file_get() after nfsd_file_acquire_local()) and an entry-time nfsd_net reference (from its first nfsd_net_try_get()) embedded as nf->nf_net. Both are leaked on the failure path, pinning one nfsd_file (and the underlying struct file, dentry, inode) and one nfsd_net_ref per occurrence, which blocks nfsd_net and netns teardown. Fix by releasing the caller-owned file ref and its net ref through the existing helper, using a stack-local RCU pointer so the helper can xchg it out, then returning -ENXIO so callers do not dereference a localio whose slot has been cleared: struct nfsd_file __rcu *tmp = RCU_INITIALIZER(localio); nfs_to_nfsd_file_put_local(pnf); nfs_to_nfsd_file_put_local(&tmp); localio = ERR_PTR(-ENXIO); The trailing nfs_to_nfsd_net_put(net) continues to release the outer net ref, so all three nfsd_net_try_get() increments are balanced on the error branch.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
fdd015de767977f21892329af5e12276eb80375f < 5215e734bf7cba18237155f8cb2a0accb60ca339 fdd015de767977f21892329af5e12276eb80375f < 9f59b05423ed381f8cdeaaae4bd6778adcb6865c fdd015de767977f21892329af5e12276eb80375f < ca018c19e0ba38975e5ddc3ef8117d5b734313aa 55735dc5a0ee0c0fc14cb51e005eae862906a410 7cac8a129fc53497f9ee5d66fca55a245d009b97 6.15.10 < 6.16 6.16.1 < 6.17
Linux / Linux
6.17

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/5215e734bf7cba18237155f8cb2a0accb60ca339 git.kernel.org: https://git.kernel.org/stable/c/9f59b05423ed381f8cdeaaae4bd6778adcb6865c git.kernel.org: https://git.kernel.org/stable/c/ca018c19e0ba38975e5ddc3ef8117d5b734313aa