* CVE-2026-89715: NFS/localio: fix ref leak on nfs_uuid_add_file failure
@ 2026-09-11 19:46 Greg Kroah-Hartman
0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-11 19:46 UTC (permalink / raw)
To: linux-cve-announce; +Cc: Greg Kroah-Hartman
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
NFS/localio: fix ref leak on nfs_uuid_add_file failure
When nfs_uuid_add_file() races with nfs_uuid_put() tearing down
uuid->net, it returns -ENXIO without publishing nfl->nfs_uuid via
rcu_assign_pointer(). nfs_open_local_fh() then enters its error
branch and only releases the slot's file ref and its paired net
ref plus its own entry-time net ref, while the close path is a
no-op:
nfs_close_local_fh()
nfs_uuid = rcu_dereference(nfl->nfs_uuid);
if (!nfs_uuid) { rcu_read_unlock(); return; } /* always */
nfsd_open_local_fh() returns localio holding a caller-owned +1
nfsd_file reference (from nfsd_file_get() after
nfsd_file_acquire_local()) and an entry-time nfsd_net reference
(from its first nfsd_net_try_get()) embedded as nf->nf_net. Both
are leaked on the failure path, pinning one nfsd_file (and the
underlying struct file, dentry, inode) and one nfsd_net_ref per
occurrence, which blocks nfsd_net and netns teardown.
Fix by releasing the caller-owned file ref and its net ref through
the existing helper, using a stack-local RCU pointer so the helper
can xchg it out, then returning -ENXIO so callers do not
dereference a localio whose slot has been cleared:
struct nfsd_file __rcu *tmp = RCU_INITIALIZER(localio);
nfs_to_nfsd_file_put_local(pnf);
nfs_to_nfsd_file_put_local(&tmp);
localio = ERR_PTR(-ENXIO);
The trailing nfs_to_nfsd_net_put(net) continues to release the
outer net ref, so all three nfsd_net_try_get() increments are
balanced on the error branch.
The Linux kernel CVE team has assigned CVE-2026-89715 to this issue.
Affected and fixed versions
===========================
Issue introduced in 6.17 with commit fdd015de767977f21892329af5e12276eb80375f and fixed in 6.18.50 with commit 5215e734bf7cba18237155f8cb2a0accb60ca339
Issue introduced in 6.17 with commit fdd015de767977f21892329af5e12276eb80375f and fixed in 7.2.4 with commit 9f59b05423ed381f8cdeaaae4bd6778adcb6865c
Issue introduced in 6.17 with commit fdd015de767977f21892329af5e12276eb80375f and fixed in 7.3-rc1 with commit ca018c19e0ba38975e5ddc3ef8117d5b734313aa
Issue introduced in 6.15.10 with commit 55735dc5a0ee0c0fc14cb51e005eae862906a410
Issue introduced in 6.16.1 with commit 7cac8a129fc53497f9ee5d66fca55a245d009b97
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-89715
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
fs/nfs_common/nfslocalio.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/5215e734bf7cba18237155f8cb2a0accb60ca339
https://git.kernel.org/stable/c/9f59b05423ed381f8cdeaaae4bd6778adcb6865c
https://git.kernel.org/stable/c/ca018c19e0ba38975e5ddc3ef8117d5b734313aa
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-09-11 20:03 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-11 19:46 CVE-2026-89715: NFS/localio: fix ref leak on nfs_uuid_add_file failure Greg Kroah-Hartman
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.