CVE-2026-89687Medium· 5.5▾ SunlitA flaw was found in the Linux kernel's Network File System Daemon (nfsd). The `nfsd_file_do_acquire()` function might attempt to use a file that has not been fully opened, as the `->atomic_open` operation could return success prematurely. …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
— → 5.9
0.2% → 0.5%
— → 5.9
none → medium
— → 7.5
none → high
7.5 → 5.9
high → medium
5.9 → 7.5
medium → high
7.5 → 5.9
high → medium
Last analysed / modified upstream
5.9 → 5.5
A flaw was found in the Linux kernel's Network File System Daemon (nfsd). The nfsd_file_do_acquire() function might attempt to use a file that has not been fully opened, as the ->atomic_open operation could return success prematurely. While this scenario is considered highly improbable, it could lead to incorrect file operations and potential system instability or denial of service under specific, rare conditions.
kernel: nfsd: ensure nfsd_file_do_acquire() does not use a non-opened file — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-21.
Affected:
No fix planned:
Not affected:
Fix deferred
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-88341Medium· 5.5A reachable assertion vulnerability exists in YARA 4.5.8 when loading crafted .yrc compiled rule files
CVE-2026-80997Medium· 5.5kernel: net: ipa: fix stalled modem TX queue after runtime resume (CVE-2026-80997)
CVE-2026-89500High· 7.0kernel: ring-buffer: Make cpu_buffer::free_page a buffer_data_read_page (CVE-2026-89500)
CVE-2026-89501High· 7.0kernel: ring-buffer: Hold cpu_buffer::lock when resizing a subbuf (CVE-2026-89501)
CVE-2026-89503Medium· 5.5kernel: ring-buffer: Fix subbuf resize race with ring_buffer_alloc_read_page() (CVE-2026-89503)
CVE-2026-89521Medium· 5.5kernel: sched/core: Handle pick_task() releasing the rq lock (CVE-2026-89521)