From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 440C358497B for ; Fri, 11 Sep 2026 20:03:54 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789157040; cv=none; b=EvIBBf5Yk4MEExtha/GnuD8Fm26BaHmqfFX49GYUirSd7gQSa9sSs6tF9ZoTkvPz39qLE9ht6xCACpYfCNqT1tAagRJCgxZ3cWZWE7ReCXgWqd5m8ODB2hc4rboNEF5gBvCjYjOyjFLlVt0upvxQpINbk2EhhweBSgsvb2kw3u0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789157040; c=relaxed/simple; bh=VGPdFzSUGtdxYaFmBmHpmP1MsId49dpswdfdmWb7ZwY=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=Rs5lUE3RhoH6rS1xdvbhitsrJ5KnlHrvxnr8decf6mh2BaNIHgQqc7zpI4ckR/C+e5nhMnOqM9Dnn0K9JuisHDWmUG6rSF4DRN8yFjcXqUb+qbeBhKiNNnF0v9aHQ4JrgvsPIEH7Co6rGNv4hEStZIWya/wh73rS/Wp0TH3HW5k= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=H2BiiqB8; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="H2BiiqB8" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 2F0741F00898; Fri, 11 Sep 2026 20:03:52 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789157033; bh=iU9Y+rJsV1H0vT85xYQW1yeC0Lkl6ExFC0zqfmqECS4=; h=From:To:Cc:Subject:Date:Reply-To; b=H2BiiqB8yc8XCbB1CRIAMQt0EnbmFwI2OgkykZg1N/O3Wf4o0LXRoc70UHt9rFvHy zsKImiO8/GM+TnSDOJtctPHPSNToMX+UJLpRpJE4VDy6yHTZs4fecyMVftFiv5tzTK lht85FQl1Bs8Ri+u+rGNfQ43y6/P2lshV8YgVcE4= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89715: NFS/localio: fix ref leak on nfs_uuid_add_file failure Date: Fri, 11 Sep 2026 21:46:44 +0200 Message-ID: <2026091159-CVE-2026-89715-e915@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3651; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=STX2/EwIxSSVuX+/uzzVEJF6/Ss9UDnefkMWKRd4J5c=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIttn7+85+PK2SZVE8rmexQtUz6SKvvL211E80Lrq+ pPtuW2qHbEsDIJMDLJiiixftvEc3V9xSNHL0PY0zBxWJpAhDFycAjCRa0oM8zOFn6xYJa+5jMdN s3dTzPpr2TPypzPMZNRVZc9ZL3/1i0/lbqstuy6/K4n9AgA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: NFS/localio: fix ref leak on nfs_uuid_add_file failure When nfs_uuid_add_file() races with nfs_uuid_put() tearing down uuid->net, it returns -ENXIO without publishing nfl->nfs_uuid via rcu_assign_pointer(). nfs_open_local_fh() then enters its error branch and only releases the slot's file ref and its paired net ref plus its own entry-time net ref, while the close path is a no-op: nfs_close_local_fh() nfs_uuid = rcu_dereference(nfl->nfs_uuid); if (!nfs_uuid) { rcu_read_unlock(); return; } /* always */ nfsd_open_local_fh() returns localio holding a caller-owned +1 nfsd_file reference (from nfsd_file_get() after nfsd_file_acquire_local()) and an entry-time nfsd_net reference (from its first nfsd_net_try_get()) embedded as nf->nf_net. Both are leaked on the failure path, pinning one nfsd_file (and the underlying struct file, dentry, inode) and one nfsd_net_ref per occurrence, which blocks nfsd_net and netns teardown. Fix by releasing the caller-owned file ref and its net ref through the existing helper, using a stack-local RCU pointer so the helper can xchg it out, then returning -ENXIO so callers do not dereference a localio whose slot has been cleared: struct nfsd_file __rcu *tmp = RCU_INITIALIZER(localio); nfs_to_nfsd_file_put_local(pnf); nfs_to_nfsd_file_put_local(&tmp); localio = ERR_PTR(-ENXIO); The trailing nfs_to_nfsd_net_put(net) continues to release the outer net ref, so all three nfsd_net_try_get() increments are balanced on the error branch. The Linux kernel CVE team has assigned CVE-2026-89715 to this issue. Affected and fixed versions =========================== Issue introduced in 6.17 with commit fdd015de767977f21892329af5e12276eb80375f and fixed in 6.18.50 with commit 5215e734bf7cba18237155f8cb2a0accb60ca339 Issue introduced in 6.17 with commit fdd015de767977f21892329af5e12276eb80375f and fixed in 7.2.4 with commit 9f59b05423ed381f8cdeaaae4bd6778adcb6865c Issue introduced in 6.17 with commit fdd015de767977f21892329af5e12276eb80375f and fixed in 7.3-rc1 with commit ca018c19e0ba38975e5ddc3ef8117d5b734313aa Issue introduced in 6.15.10 with commit 55735dc5a0ee0c0fc14cb51e005eae862906a410 Issue introduced in 6.16.1 with commit 7cac8a129fc53497f9ee5d66fca55a245d009b97 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89715 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: fs/nfs_common/nfslocalio.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/5215e734bf7cba18237155f8cb2a0accb60ca339 https://git.kernel.org/stable/c/9f59b05423ed381f8cdeaaae4bd6778adcb6865c https://git.kernel.org/stable/c/ca018c19e0ba38975e5ddc3ef8117d5b734313aa