{"id":"CVE-2026-89664","title":"kernel: nfsd: release OPEN-decoded posix ACLs via op_release (CVE-2026-89664)","summary":"A flaw was found in the Linux kernel's Network File System Daemon (nfsd). When processing malformed NFSv4 OPEN compound operations that include valid Portable Operating System Interface (POSIX) Access Control List (ACL) attributes, the ker…","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-911","vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","affected":["enterprise_linux 10"],"published":"2026-09-11","updated":"2026-09-15","sourceUpdated":"2026-09-15T11:02:24+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89664.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89664.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89664"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532528"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89664"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89664"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89664.mbox"},{"url":"https://git.kernel.org/stable/c/5b3a7d7c23c071efe12dd1bc1d2e5f97c4892921"},{"url":"https://git.kernel.org/stable/c/8215892993ea9f5231da4fa9eb42428a286fce8b"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00488,"epssPercentile":0.40943,"scores":{"vendor":5.9,"cna":7.5},"ingestedAt":"2026-09-14T15:23:07.473Z","slug":"CVE-2026-89664","body":"## Overview\n\nA flaw was found in the Linux kernel's Network File System Daemon (nfsd). When processing malformed NFSv4 OPEN compound operations that include valid Portable Operating System Interface (POSIX) Access Control List (ACL) attributes, the kernel fails to release allocated memory resources. This oversight can lead to a memory leak, which, over time, could exhaust system memory and result in a Denial of Service (DoS) for affected systems.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10 · no fix planned: Red Hat Enterprise Linux 10 · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89664.json)\n\n**kernel: nfsd: release OPEN-decoded posix ACLs via op_release** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-15.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 10\n\nNot affected:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nAffected","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":203910,"id":"CVE-2026-89664","ts":1789490220609,"field":"cvss","old":"5.9","new":"7"},{"seq":203909,"id":"CVE-2026-89664","ts":1789490220609,"field":"severity","old":"medium","new":"high"},{"seq":202832,"id":"CVE-2026-89664","ts":1789403732588,"field":"cvss","old":"7.5","new":"5.9"},{"seq":202831,"id":"CVE-2026-89664","ts":1789403732588,"field":"severity","old":"high","new":"medium"},{"seq":197781,"id":"CVE-2026-89664","ts":1789384318825,"field":"cvss","old":"5.9","new":"7.5"},{"seq":197780,"id":"CVE-2026-89664","ts":1789384318825,"field":"severity","old":"medium","new":"high"},{"seq":183387,"id":"CVE-2026-89664","ts":1789356675152,"field":"cvss","old":"7.5","new":"5.9"},{"seq":183386,"id":"CVE-2026-89664","ts":1789356675152,"field":"severity","old":"high","new":"medium"},{"seq":153524,"id":"CVE-2026-89664","ts":1789285351142,"field":"cvss","old":null,"new":"7.5"},{"seq":153523,"id":"CVE-2026-89664","ts":1789285351142,"field":"severity","old":"none","new":"high"},{"seq":147057,"id":"CVE-2026-89664","ts":1789270194974,"field":"cvss","old":null,"new":"5.9"},{"seq":147056,"id":"CVE-2026-89664","ts":1789270194974,"field":"severity","old":"none","new":"medium"}]}