CVE-2026-89664High· 7.0▾ TwilightA flaw was found in the Linux kernel's Network File System Daemon (nfsd). When processing malformed NFSv4 OPEN compound operations that include valid Portable Operating System Interface (POSIX) Access Control List (ACL) attributes, the ker…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 38.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
0.2% → 0.5%
— → 5.9
none → medium
— → 7.5
none → high
7.5 → 5.9
high → medium
5.9 → 7.5
medium → high
7.5 → 5.9
high → medium
Last analysed / modified upstream
5.9 → 7
medium → high
A flaw was found in the Linux kernel's Network File System Daemon (nfsd). When processing malformed NFSv4 OPEN compound operations that include valid Portable Operating System Interface (POSIX) Access Control List (ACL) attributes, the kernel fails to release allocated memory resources. This oversight can lead to a memory leak, which, over time, could exhaust system memory and result in a Denial of Service (DoS) for affected systems.
kernel: nfsd: release OPEN-decoded posix ACLs via op_release — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-15.
Affected:
No fix planned:
Not affected:
Affected
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-89646Medium· 5.5kernel: ceph: fix leaked inode reference on writeback abort at umount (CVE-2026-89646)
CVE-2026-89692Medium· 5.5kernel: nfsd: clear CALLBACK_RUNNING on failed delegation recall queue (CVE-2026-89692)
CVE-2026-89645Medium· 5.5kernel: btrfs: drop recovered reloc root refs on recovery failure (CVE-2026-89645)
CVE-2026-89683High· 7.0kernel: nfsd: fix dentry ref leak on V4ROOT export filehandle lookup (CVE-2026-89683)
CVE-2026-80997Medium· 5.5kernel: net: ipa: fix stalled modem TX queue after runtime resume (CVE-2026-80997)
CVE-2026-89500High· 7.0kernel: ring-buffer: Make cpu_buffer::free_page a buffer_data_read_page (CVE-2026-89500)