---
id: CVE-2026-89664
title: 'kernel: nfsd: release OPEN-decoded posix ACLs via op_release (CVE-2026-89664)'
summary: >-
  A flaw was found in the Linux kernel's Network File System Daemon (nfsd). When
  processing malformed NFSv4 OPEN compound operations that include valid
  Portable Operating System Interface (POSIX) Access Control List (ACL)
  attributes, the ker…
severity: high
cvss: 7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'
cvssSource: vendor
cwe: CWE-911
vendor: Red Hat
product: Red Hat Enterprise Linux 10
affected:
  - enterprise_linux 10
published: '2026-09-11'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T11:02:24+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89664.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89664.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-89664'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2532528'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-89664'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89664'
  - url: >-
      https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89664.mbox
  - url: 'https://git.kernel.org/stable/c/5b3a7d7c23c071efe12dd1bc1d2e5f97c4892921'
  - url: 'https://git.kernel.org/stable/c/8215892993ea9f5231da4fa9eb42428a286fce8b'
tags:
  - csaf
  - vex
  - red-hat
  - cve.org
epss: 0.00488
epssPercentile: 0.39338
scores:
  vendor: 5.9
  cna: 7.5
ingestedAt: '2026-09-14T15:23:07.473Z'
---

## Overview

A flaw was found in the Linux kernel's Network File System Daemon (nfsd). When processing malformed NFSv4 OPEN compound operations that include valid Portable Operating System Interface (POSIX) Access Control List (ACL) attributes, the kernel fails to release allocated memory resources. This oversight can lead to a memory leak, which, over time, could exhaust system memory and result in a Denial of Service (DoS) for affected systems.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10 · no fix planned: Red Hat Enterprise Linux 10 · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89664.json)

**kernel: nfsd: release OPEN-decoded posix ACLs via op_release** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-15.

Affected:

- Red Hat Enterprise Linux 10

No fix planned:

- Red Hat Enterprise Linux 10

Not affected:

- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 4

## Remediation

Affected
