CVE-2026-89711High· 8.2▾ TwilightIn the Linux kernel, the following vulnerability has been resolved: NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check The header for commit e75b23f9e323 ("nfsd: check d_can_lookup in fh_verify of directories") details the assumptio…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CVEORG
0.2%
— → 5.9
none → medium
— → 5.9
none → medium
— → 8.2
none → high
Last analysed / modified upstream
8.2 → 5.9
high → medium
5.9 → 8.2
medium → high
0.2% → 0.4%
In the Linux kernel, the following vulnerability has been resolved:
NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check
The header for commit e75b23f9e323 ("nfsd: check d_can_lookup in fh_verify of directories") details the assumption that justified adding the WARN_ON_ONCE to nfsd_mode_check(), that assumption is invalid (in the case of NFS reexport).
When NFSD exports an NFS filesystem it is very possible for nfsd_mode_check() to encounter a @dentry that doesn't have i_op->lookup (see nfs_fhget()'s NFS_ATTR_FATTR_MOUNTPOINT and NFS_ATTR_FATTR_V4_REFERRAL handling, and d_flags_for_inode()).
So remove nfsd_mode_check()'s WARN_ON_ONCE(). The nfserr_notdir return on that branch must stay. It guards the subsequent lookup_one_unlocked() -> __lookup_slow() path, which calls inode->i_op->lookup() with no NULL check, so returning nfserr_notdir is what keeps a client LOOKUP into such a @dentry from dereferencing a NULL method pointer.
Linux >= e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c < ae251937c6f0237e5b555a5e4ba4595b8206e865Linux >= e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c < e145e8d67a5d41c72d322e7f87ab474d39d9dfb7Linux >= e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c < 9f4434893a2783f7384d993cea883aff3fb7a52dLinux >= e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c < 2ef131323999539038e306773c8256403834361bLinux >= e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c < b55b4d880bb080fa10eb08ba21a5d8679b8102feLinux >= e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c < 7ef182a8fe9c12b0d936880b1e504840639aa009Linux >= e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c < a275de3bac5635514ca830f2e46b5ff0e66b5c4cLinux >= e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c < aa0cf48a448c5a9fe1a1e880899ecd589ce39e6eLinux 4.8Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-90068NoneIn the Linux kernel, the following vulnerability has been resolved: ASoC: dapm: Fix off-by-one check on the second enum channel The snd_soc_dapm_put_enum_double() rejects item[0] once it reaches e->items, but it lets item[1] be equal t…
CVE-2026-90090NoneIn the Linux kernel, the following vulnerability has been resolved: Bluetooth: btmtksdio: Fix out-of-bounds DMA read in the TX path btmtksdio_tx_packet() rounds the transfer size up to the SDIO block size of 256 bytes, but hands the ho…
CVE-2026-90093High· 7.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: access chan->conn safely in get/setsockopt Since commit b66774b48dd9 ("Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref") l2cap_chan:…
CVE-2026-90098NoneIn the Linux kernel, the following vulnerability has been resolved: net: sparx5: fix sleep in atomic context in MAC table access sparx5_set_rx_mode() runs with netif_addr_lock_bh held and iterates dev->mc via __dev_mc_sync(), which per…
CVE-2026-90121NoneIn the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v5: Clear per-CPU IRS data on teardown IRS affinity setup publishes an IRS pointer and IAFFID state in the per-CPU data before the remaining IRS initializa…
CVE-2026-90156NoneIn the Linux kernel, the following vulnerability has been resolved: ksmbd: safely discard unregistered deferred locks When vfs_lock_file() defers a lock, smb2_lock() puts its ksmbd_lock on rollback_list before allocating and registerin…