---
id: CVE-2026-89711
title: 'NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check'
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check

  The header for commit e75b23f9e323 ("nfsd: check d_can_lookup in
  fh_verify of directories") details the assumptio…
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H'
cvssSource: cna
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c <
    ae251937c6f0237e5b555a5e4ba4595b8206e865
  - >-
    Linux >= e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c <
    e145e8d67a5d41c72d322e7f87ab474d39d9dfb7
  - >-
    Linux >= e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c <
    9f4434893a2783f7384d993cea883aff3fb7a52d
  - >-
    Linux >= e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c <
    2ef131323999539038e306773c8256403834361b
  - >-
    Linux >= e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c <
    b55b4d880bb080fa10eb08ba21a5d8679b8102fe
  - >-
    Linux >= e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c <
    7ef182a8fe9c12b0d936880b1e504840639aa009
  - >-
    Linux >= e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c <
    a275de3bac5635514ca830f2e46b5ff0e66b5c4c
  - >-
    Linux >= e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c <
    aa0cf48a448c5a9fe1a1e880899ecd589ce39e6e
  - Linux 4.8
published: '2026-09-11'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T12:02:10.683Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-89711'
references:
  - url: 'https://git.kernel.org/stable/c/ae251937c6f0237e5b555a5e4ba4595b8206e865'
  - url: 'https://git.kernel.org/stable/c/e145e8d67a5d41c72d322e7f87ab474d39d9dfb7'
  - url: 'https://git.kernel.org/stable/c/9f4434893a2783f7384d993cea883aff3fb7a52d'
  - url: 'https://git.kernel.org/stable/c/2ef131323999539038e306773c8256403834361b'
  - url: 'https://git.kernel.org/stable/c/b55b4d880bb080fa10eb08ba21a5d8679b8102fe'
  - url: 'https://git.kernel.org/stable/c/7ef182a8fe9c12b0d936880b1e504840639aa009'
  - url: 'https://git.kernel.org/stable/c/a275de3bac5635514ca830f2e46b5ff0e66b5c4c'
  - url: 'https://git.kernel.org/stable/c/aa0cf48a448c5a9fe1a1e880899ecd589ce39e6e'
tags:
  - cve.org
epss: 0.00633
epssPercentile: 0.48085
ingestedAt: '2026-09-14T15:23:07.449Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check

The header for commit e75b23f9e323 ("nfsd: check d_can_lookup in
fh_verify of directories") details the assumption that justified
adding the WARN_ON_ONCE to nfsd_mode_check(), that assumption is
invalid (in the case of NFS reexport).

When NFSD exports an NFS filesystem it is very possible for
nfsd_mode_check() to encounter a @dentry that doesn't have
i_op->lookup (see nfs_fhget()'s NFS_ATTR_FATTR_MOUNTPOINT and
NFS_ATTR_FATTR_V4_REFERRAL handling, and d_flags_for_inode()).

So remove nfsd_mode_check()'s WARN_ON_ONCE(). The nfserr_notdir
return on that branch must stay. It guards the subsequent
lookup_one_unlocked() -> __lookup_slow() path, which calls
inode->i_op->lookup() with no NULL check, so returning nfserr_notdir
is what keeps a client LOOKUP into such a @dentry from dereferencing
a NULL method pointer.

## Affected

- `Linux >= e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c < ae251937c6f0237e5b555a5e4ba4595b8206e865`
- `Linux >= e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c < e145e8d67a5d41c72d322e7f87ab474d39d9dfb7`
- `Linux >= e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c < 9f4434893a2783f7384d993cea883aff3fb7a52d`
- `Linux >= e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c < 2ef131323999539038e306773c8256403834361b`
- `Linux >= e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c < b55b4d880bb080fa10eb08ba21a5d8679b8102fe`
- `Linux >= e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c < 7ef182a8fe9c12b0d936880b1e504840639aa009`
- `Linux >= e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c < a275de3bac5635514ca830f2e46b5ff0e66b5c4c`
- `Linux >= e75b23f9e323b1e0759619c39d5a9f7a3a5d9d2c < aa0cf48a448c5a9fe1a1e880899ecd589ce39e6e`
- `Linux 4.8`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
