From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1AFB6584969 for ; Fri, 11 Sep 2026 20:03:54 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789157042; cv=none; b=mybifUQM9bpIqJSHe8HNansqWPprbVh2hr+x9EeiIB8efdE9cjFEHK1y6KS06JZOY+MrmkLUQLNuw+qEsUtFfVsYU6LBxnt43zA0GauJKmZccPhorkV9jnCSgPbQbJpLfnAcqZ8zscUztfDEAyN59AJsGAY7jwzrT9TaGpFhzNI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789157042; c=relaxed/simple; bh=YfW+fP5KD9X4L9cv2P4FnLWkOT6lmbdoVL8m8/97ZSQ=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=c619+JlYCbNRLtnMX68vCZ9H0iAPks8ZWjlfDuWmMQh4PvhJ/mVhcv6JG7l9Jt+IzfyUdxpweQLzHZ8SQEtDbuzaEoU9ftbXjPh7pUMw4FDpx9RdFUicIMrUhRiG+DGkYOSnG7TqYhSzoNk9orB0xuAhnflJW/IlQSFQkRvcQpw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=lBXJJbMW; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="lBXJJbMW" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 2A74F1F000FF; Fri, 11 Sep 2026 20:03:49 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789157030; bh=AhGTHPtPjI5TZ8BGm0u7PTudRUOa4n78yrcCdrLkVLc=; h=From:To:Cc:Subject:Date:Reply-To; b=lBXJJbMWXfQyTZ9+4Pf1URStmvUtlzjU1LiMHfMLx+AuX08tWsdU4czQgJGPNdJo7 /sxdhXGTWDJ0S9tcPLvHZHmMzHWyUJGSIsfZeaIZCA2X8vtn5EmUOk0d96ytHK+RFt PWaz2nhz3Cms+KwO2scO0m6GLyukBex+W1ig9RFY= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89714: NFS: fix delegation_hash_table leak when nfs4_server_common_setup() fails Date: Fri, 11 Sep 2026 21:46:43 +0200 Message-ID: <2026091158-CVE-2026-89714-1ed8@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3401; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=CINVMHWjOVDNEPagHaPL0Bw5chQvxvjxdL7CIMCGDNc=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLItskQpwiJXvrM5MC/09kMvq8Rtl+MsNLIYfPLw2fV d31/ODdEcvCIMjEICumyPJlG8/R/RWHFL0MbU/DzGFlAhnCwMUpABOZOIdhfhTv74CNQX4ff38N 8+rTO2AVELRPjGF+kILJo/tLa97KHJWKvpdbxTS/4/EHAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: NFS: fix delegation_hash_table leak when nfs4_server_common_setup() fails nfs4_server_common_setup() allocates server->delegation_hash_table first, but server->destroy - the only path that frees the table via nfs4_destroy_server() - is not assigned until the very end of the function. If any intermediate step fails (the is_ds_only_client() check, nfs4_init_session(), nfs4_get_rootfh(), or nfs_probe_server()), the function returns with server->destroy still NULL, so the caller's nfs_free_server() skips the destroy callback and the hash table is leaked (4 KiB per attempt with the default delegation watermark). This is trivially reachable from userspace: every failed NFSv4 mount leaks one allocation. A client that persistently retries a mount that cannot succeed leaks kernel memory without bound. Observed in production where a Longhorn backup poller retried mount.nfs4 against an NFSv3-only server roughly 10 times per second, leaking ~3.4 GiB of unreclaimable slab (kmalloc-rnd-13-4k) per day; the node accumulated 12 GiB of leaked slab before the source was identified via the kmem:kmalloc tracepoint (call_site=nfs4_delegation_hash_alloc). Reproducer: # server exports NFSv3 only (or export path absent for v4) while :; do mount -t nfs4 :/missing /mnt; done # watch SUnreclaim in /proc/meminfo grow 4 KiB per iteration Free the table on the error paths between the allocation and the assignment of server->destroy. The Linux kernel CVE team has assigned CVE-2026-89714 to this issue. Affected and fixed versions =========================== Issue introduced in 6.17 with commit f5b3108e6a14418b120a3c38ca589b8d6cf87627 and fixed in 6.18.50 with commit f3adf1643517357221422c05986d6de5df7b9913 Issue introduced in 6.17 with commit f5b3108e6a14418b120a3c38ca589b8d6cf87627 and fixed in 7.2.4 with commit 0fd2b9687dae36be5b84eab39b4c627bb7ab33b3 Issue introduced in 6.17 with commit f5b3108e6a14418b120a3c38ca589b8d6cf87627 and fixed in 7.3-rc1 with commit 2092f5b38f88be306140c77aeeeb43fc1adacacc Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89714 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: fs/nfs/nfs4client.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/f3adf1643517357221422c05986d6de5df7b9913 https://git.kernel.org/stable/c/0fd2b9687dae36be5b84eab39b4c627bb7ab33b3 https://git.kernel.org/stable/c/2092f5b38f88be306140c77aeeeb43fc1adacacc