7.5
CVE-2026-89707
- EPSS 0.6%
- Veröffentlicht 11.09.2026 19:46:23
- Zuletzt bearbeitet 14.09.2026 13:19:20
- Erkennungen
nfsd: release path refs on follow_down() error
In the Linux kernel, the following vulnerability has been resolved:
nfsd: release path refs on follow_down() error
nfsd_cross_mnt() initializes a local struct path with mntget() and
dget() before calling follow_down(). On a negative return the error
arm jumps to out without releasing those references:
err = follow_down(&path, follow_flags);
if (err < 0)
goto out;
follow_down() never drops the caller's entry-time refs on any error
sub-case; for example a pre-cross d_manage() failure leaves path
untouched, so the mntget()/dget() taken on entry survive the call.
Every other early-exit arm in nfsd_cross_mnt() (other-namespace
return, IS_ERR(exp2), and the success tail after the swap) already
calls path_put(&path); the err < 0 arm is the lone omission. The
leak inflates mnt_count and d_count on each failed cross-mount,
blocking umount and pinning dentries against the shrinker, and is
reachable by any authenticated NFS client through nfsd_lookup_dentry
or the NFSv4 READDIR encode path.
Fix by calling path_put(&path) before the goto out in the err < 0
arm so the entry-time refs are released on all follow_down() error
returns.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
cc53ce53c86924bfe98a12ea20b7465038a08792
Version <
085cfde7c2186acaad103f02d2c25435ad5224e9
Status
affected
Version
cc53ce53c86924bfe98a12ea20b7465038a08792
Version <
194316df81263519156ebe714c4a286bee00e5be
Status
affected
Version
cc53ce53c86924bfe98a12ea20b7465038a08792
Version <
467d56fd3ff57447a790c6dc3ede2d02a947d224
Status
affected
Version
cc53ce53c86924bfe98a12ea20b7465038a08792
Version <
2bc4343308d85ee4e0dd3877b384306c96f114c2
Status
affected
Version
cc53ce53c86924bfe98a12ea20b7465038a08792
Version <
6cba08dc1922140d260cfeb30bbda4ee1bf869d8
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
2.6.38
Status
affected
Version
0
Version <
2.6.38
Status
unaffected
Version <=
6.6.*
Version
6.6.157
Status
unaffected
Version <=
6.12.*
Version
6.12.109
Status
unaffected
Version <=
6.18.*
Version
6.18.50
Status
unaffected
Version <=
7.2.*
Version
7.2.4
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.6% | 0.47 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
https://git.kernel.org/stable/c/194316df81263519156ebe714c4a286bee00e5be
https://git.kernel.org/stable/c/467d56fd3ff57447a790c6dc3ede2d02a947d224
https://git.kernel.org/stable/c/2bc4343308d85ee4e0dd3877b384306c96f114c2
https://git.kernel.org/stable/c/6cba08dc1922140d260cfeb30bbda4ee1bf869d8
https://git.kernel.org/stable/c/085cfde7c2186acaad103f02d2c25435ad5224e9