{"id":"CVE-2026-89715","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nNFS/localio: fix ref leak on nfs_uuid_add_file failure\n\nWhen nfs_uuid_add_file() races with nfs_uuid_put() tearing down\nuuid->net, it returns -ENXIO without publishing …","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nNFS/localio: fix ref leak on nfs_uuid_add_file failure\n\nWhen nfs_uuid_add_file() races with nfs_uuid_put() tearing down\nuuid->net, it returns -ENXIO without publishing …","severity":"medium","vendor":"Linux","product":"Linux","affected":["Linux >= fdd015de767977f21892329af5e12276eb80375f < 5215e734bf7cba18237155f8cb2a0accb60ca339","Linux >= fdd015de767977f21892329af5e12276eb80375f < 9f59b05423ed381f8cdeaaae4bd6778adcb6865c","Linux >= fdd015de767977f21892329af5e12276eb80375f < ca018c19e0ba38975e5ddc3ef8117d5b734313aa","Linux 55735dc5a0ee0c0fc14cb51e005eae862906a410","Linux 7cac8a129fc53497f9ee5d66fca55a245d009b97","Linux >= 6.15.10 < 6.16","Linux >= 6.16.1 < 6.17","Linux 6.17"],"published":"2026-09-11","updated":"2026-09-11","sourceUpdated":"2026-09-11T20:19:58.993","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-89715","references":[{"url":"https://git.kernel.org/stable/c/5215e734bf7cba18237155f8cb2a0accb60ca339","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9f59b05423ed381f8cdeaaae4bd6778adcb6865c","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ca018c19e0ba38975e5ddc3ef8117d5b734313aa","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89715.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89715"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532445"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89715"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89715"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89715.mbox"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ingestedAt":"2026-09-14T12:47:54.894Z","epss":0.00206,"epssPercentile":0.09441,"cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":["CWE-911"],"slug":"CVE-2026-89715","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nNFS/localio: fix ref leak on nfs_uuid_add_file failure\n\nWhen nfs_uuid_add_file() races with nfs_uuid_put() tearing down\nuuid->net, it returns -ENXIO without publishing nfl->nfs_uuid via\nrcu_assign_pointer().  nfs_open_local_fh() then enters its error\nbranch and only releases the slot's file ref and its paired net\nref plus its own entry-time net ref, while the close path is a\nno-op:\n\n    nfs_close_local_fh()\n      nfs_uuid = rcu_dereference(nfl->nfs_uuid);\n      if (!nfs_uuid) { rcu_read_unlock(); return; }  /* always */\n\nnfsd_open_local_fh() returns localio holding a caller-owned +1\nnfsd_file reference (from nfsd_file_get() after\nnfsd_file_acquire_local()) and an entry-time nfsd_net reference\n(from its first nfsd_net_try_get()) embedded as nf->nf_net.  Both\nare leaked on the failure path, pinning one nfsd_file (and the\nunderlying struct file, dentry, inode) and one nfsd_net_ref per\noccurrence, which blocks nfsd_net and netns teardown.\n\nFix by releasing the caller-owned file ref and its net ref through\nthe existing helper, using a stack-local RCU pointer so the helper\ncan xchg it out, then returning -ENXIO so callers do not\ndereference a localio whose slot has been cleared:\n\n    struct nfsd_file __rcu *tmp = RCU_INITIALIZER(localio);\n\n    nfs_to_nfsd_file_put_local(pnf);\n    nfs_to_nfsd_file_put_local(&tmp);\n    localio = ERR_PTR(-ENXIO);\n\nThe trailing nfs_to_nfsd_net_put(net) continues to release the\nouter net ref, so all three nfsd_net_try_get() increments are\nbalanced on the error branch.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Low · affected: Red Hat Enterprise Linux 10 · no fix planned: Red Hat Enterprise Linux 10 · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89715.json)","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":203865,"id":"CVE-2026-89715","ts":1789490210397,"field":"cvss","old":null,"new":"5.5"},{"seq":203864,"id":"CVE-2026-89715","ts":1789490210397,"field":"severity","old":"none","new":"medium"},{"seq":147199,"id":"CVE-2026-89715","ts":1789270200676,"field":"cvss","old":null,"new":"5.3"},{"seq":147198,"id":"CVE-2026-89715","ts":1789270200676,"field":"severity","old":"none","new":"medium"},{"seq":108952,"id":"CVE-2026-89715","ts":1789183729710,"field":"cvss","old":null,"new":"5.3"},{"seq":108951,"id":"CVE-2026-89715","ts":1789183729710,"field":"severity","old":"none","new":"medium"}]}