{"id":"CVE-2026-89687","title":"kernel: nfsd: ensure nfsd_file_do_acquire() does not use a non-opened file (CVE-2026-89687)","summary":"A flaw was found in the Linux kernel's Network File System Daemon (nfsd). The `nfsd_file_do_acquire()` function might attempt to use a file that has not been fully opened, as the `->atomic_open` operation could return success prematurely. …","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-908","vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","affected":["enterprise_linux 10","openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-21","sourceUpdated":"2026-09-21T11:41:22+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89687.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89687.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89687"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532086"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89687"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89687"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89687.mbox"},{"url":"https://git.kernel.org/stable/c/5859cc01fee06a2cd7458905a9593082fbab06e1"},{"url":"https://git.kernel.org/stable/c/a95a1cffacd0203100297001719160160f443dd6"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00488,"epssPercentile":0.39338,"scores":{"vendor":5.9,"cna":7.5},"ingestedAt":"2026-09-14T15:23:07.472Z","slug":"CVE-2026-89687","body":"## Overview\n\nA flaw was found in the Linux kernel's Network File System Daemon (nfsd). The `nfsd_file_do_acquire()` function might attempt to use a file that has not been fully opened, as the `->atomic_open` operation could return success prematurely. While this scenario is considered highly improbable, it could lead to incorrect file operations and potential system instability or denial of service under specific, rare conditions.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 10, Red Hat OpenShift Container Platform 4 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89687.json)\n\n**kernel: nfsd: ensure nfsd_file_do_acquire() does not use a non-opened file** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-21.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat OpenShift Container Platform 4\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 10\n- Red Hat OpenShift Container Platform 4\n\nNot affected:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n\n## Remediation\n\nFix deferred","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":208462,"id":"CVE-2026-89687","ts":1790005708190,"field":"cvss","old":"5.9","new":"5.5"},{"seq":202822,"id":"CVE-2026-89687","ts":1789403732547,"field":"cvss","old":"7.5","new":"5.9"},{"seq":202821,"id":"CVE-2026-89687","ts":1789403732547,"field":"severity","old":"high","new":"medium"},{"seq":197742,"id":"CVE-2026-89687","ts":1789384318650,"field":"cvss","old":"5.9","new":"7.5"},{"seq":197741,"id":"CVE-2026-89687","ts":1789384318650,"field":"severity","old":"medium","new":"high"},{"seq":183357,"id":"CVE-2026-89687","ts":1789356675028,"field":"cvss","old":"7.5","new":"5.9"},{"seq":183356,"id":"CVE-2026-89687","ts":1789356675028,"field":"severity","old":"high","new":"medium"},{"seq":153564,"id":"CVE-2026-89687","ts":1789285351301,"field":"cvss","old":null,"new":"7.5"},{"seq":153563,"id":"CVE-2026-89687","ts":1789285351301,"field":"severity","old":"none","new":"high"},{"seq":147694,"id":"CVE-2026-89687","ts":1789270211912,"field":"cvss","old":null,"new":"5.9"},{"seq":147693,"id":"CVE-2026-89687","ts":1789270211912,"field":"severity","old":"none","new":"medium"},{"seq":109448,"id":"CVE-2026-89687","ts":1789183731953,"field":"cvss","old":null,"new":"5.9"},{"seq":109447,"id":"CVE-2026-89687","ts":1789183731953,"field":"severity","old":"none","new":"medium"}]}