{"id":"CVE-2026-89667","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache\n\nThe shrinker, GC worker, and fsnotify/lease callbacks can unhash an\nnfsd_file from the rhashtabl…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache\n\nThe shrinker, GC worker, and fsnotify/lease callbacks can unhash an\nnfsd_file from the rhashtabl…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-772"],"vendor":"Linux","product":"Linux","affected":["Linux >= ffb402596147ac583f3464ff5c48feb9423e3838 < b15997b53b61c74fb4d083f7261d19f389ff854f","Linux >= ffb402596147ac583f3464ff5c48feb9423e3838 < 6d6b9f6a75c3767250e9c23ace4e384ab8f7843e","Linux >= ffb402596147ac583f3464ff5c48feb9423e3838 < 08af9593e2b472fd98c00faf1bf03bdbb7203477","Linux >= ffb402596147ac583f3464ff5c48feb9423e3838 < 40162cfea79b9510380decfdd1795b754dc9f972","Linux 6.9"],"published":"2026-09-11","updated":"2026-09-21","sourceUpdated":"2026-09-21T14:17:24.830","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-89667","references":[{"url":"https://git.kernel.org/stable/c/08af9593e2b472fd98c00faf1bf03bdbb7203477","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/40162cfea79b9510380decfdd1795b754dc9f972","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6d6b9f6a75c3767250e9c23ace4e384ab8f7843e","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b15997b53b61c74fb4d083f7261d19f389ff854f","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89667.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89667"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532484"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89667"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89667"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89667.mbox"}],"tags":["nvd","cve.org","csaf","vex","red-hat","score-dispute"],"epss":0.00512,"epssPercentile":0.42505,"scores":{"nvd":8.1,"cna":8.1,"vendor":5.5},"ingestedAt":"2026-09-14T15:23:07.473Z","slug":"CVE-2026-89667","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache\n\nThe shrinker, GC worker, and fsnotify/lease callbacks can unhash an\nnfsd_file from the rhashtable and then call\nnfsd_file_dispose_list_delayed() to move it to the per-net dispose list.\nIf nfsd_file_cache_shutdown_net() runs concurrently, its rhashtable walk\nmisses the already-unhashed file, and its drain of the per-net dispose\nlist can run before the file has been queued.  The file then sits on\nthe per-net list with no thread to drain it, leaking both the file and\nits associated state.\n\nThe GC worker and shrinker already hold nfsd_gc_lock while walking the\nLRU, but in the original code they release it before calling\nnfsd_file_dispose_list_delayed().  The fsnotify/lease path\n(nfsd_file_close_inode) has no synchronization at all.\n\nFix this by:\n\n  1. Widening nfsd_gc_lock in both nfsd_file_gc() and nfsd_file_lru_scan()\n     to cover the nfsd_file_dispose_list_delayed() call.\n\n  2. Wrapping nfsd_file_close_inode() in nfsd_gc_lock so that all three\n     callers of nfsd_file_dispose_list_delayed() hold the lock.\n\n  3. Adding a spin_lock/unlock(nfsd_gc_lock) barrier in\n     nfsd_file_cache_shutdown_net() after the purge, so that any\n     in-progress disposal has fully completed before the per-net list\n     is drained.\n\nAll operations inside the lock are non-sleeping (rhashtable lookups,\natomic bit/refcount ops, list moves, svc_wake_up), so the spinlock is\nappropriate.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89667.json)","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":208375,"id":"CVE-2026-89667","ts":1789997913184,"field":"cvss","old":"5.5","new":"8.1"},{"seq":208374,"id":"CVE-2026-89667","ts":1789997913184,"field":"severity","old":"medium","new":"high"},{"seq":203861,"id":"CVE-2026-89667","ts":1789490210252,"field":"cvss","old":"5.3","new":"5.5"},{"seq":202834,"id":"CVE-2026-89667","ts":1789403732596,"field":"cvss","old":"8.1","new":"5.3"},{"seq":202833,"id":"CVE-2026-89667","ts":1789403732596,"field":"severity","old":"high","new":"medium"},{"seq":197770,"id":"CVE-2026-89667","ts":1789384318773,"field":"cvss","old":"5.3","new":"8.1"},{"seq":197769,"id":"CVE-2026-89667","ts":1789384318773,"field":"severity","old":"medium","new":"high"},{"seq":183367,"id":"CVE-2026-89667","ts":1789356675069,"field":"cvss","old":"8.1","new":"5.3"},{"seq":183366,"id":"CVE-2026-89667","ts":1789356675069,"field":"severity","old":"high","new":"medium"},{"seq":153528,"id":"CVE-2026-89667","ts":1789285351158,"field":"cvss","old":null,"new":"8.1"},{"seq":153527,"id":"CVE-2026-89667","ts":1789285351158,"field":"severity","old":"none","new":"high"},{"seq":147117,"id":"CVE-2026-89667","ts":1789270195240,"field":"cvss","old":null,"new":"5.3"},{"seq":147116,"id":"CVE-2026-89667","ts":1789270195240,"field":"severity","old":"none","new":"medium"},{"seq":108876,"id":"CVE-2026-89667","ts":1789183729362,"field":"cvss","old":null,"new":"5.3"},{"seq":108875,"id":"CVE-2026-89667","ts":1789183729362,"field":"severity","old":"none","new":"medium"}]}