-

CVE-2026-89715

NFS/localio: fix ref leak on nfs_uuid_add_file failure

In the Linux kernel, the following vulnerability has been resolved:

NFS/localio: fix ref leak on nfs_uuid_add_file failure

When nfs_uuid_add_file() races with nfs_uuid_put() tearing down
uuid->net, it returns -ENXIO without publishing nfl->nfs_uuid via
rcu_assign_pointer().  nfs_open_local_fh() then enters its error
branch and only releases the slot's file ref and its paired net
ref plus its own entry-time net ref, while the close path is a
no-op:

    nfs_close_local_fh()
      nfs_uuid = rcu_dereference(nfl->nfs_uuid);
      if (!nfs_uuid) { rcu_read_unlock(); return; }  /* always */

nfsd_open_local_fh() returns localio holding a caller-owned +1
nfsd_file reference (from nfsd_file_get() after
nfsd_file_acquire_local()) and an entry-time nfsd_net reference
(from its first nfsd_net_try_get()) embedded as nf->nf_net.  Both
are leaked on the failure path, pinning one nfsd_file (and the
underlying struct file, dentry, inode) and one nfsd_net_ref per
occurrence, which blocks nfsd_net and netns teardown.

Fix by releasing the caller-owned file ref and its net ref through
the existing helper, using a stack-local RCU pointer so the helper
can xchg it out, then returning -ENXIO so callers do not
dereference a localio whose slot has been cleared:

    struct nfsd_file __rcu *tmp = RCU_INITIALIZER(localio);

    nfs_to_nfsd_file_put_local(pnf);
    nfs_to_nfsd_file_put_local(&tmp);
    localio = ERR_PTR(-ENXIO);

The trailing nfs_to_nfsd_net_put(net) continues to release the
outer net ref, so all three nfsd_net_try_get() increments are
balanced on the error branch.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version fdd015de767977f21892329af5e12276eb80375f
Version < 5215e734bf7cba18237155f8cb2a0accb60ca339
Status affected
Version fdd015de767977f21892329af5e12276eb80375f
Version < 9f59b05423ed381f8cdeaaae4bd6778adcb6865c
Status affected
Version fdd015de767977f21892329af5e12276eb80375f
Version < ca018c19e0ba38975e5ddc3ef8117d5b734313aa
Status affected
Version 55735dc5a0ee0c0fc14cb51e005eae862906a410
Status affected
Version 7cac8a129fc53497f9ee5d66fca55a245d009b97
Status affected
Version 6.15.10
Version < 6.16
Status affected
Version 6.16.1
Version < 6.17
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.17
Status affected
Version 0
Version < 6.17
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.097
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/5215e734bf7cba18237155f8cb2a0accb60ca339
https://git.kernel.org/stable/c/9f59b05423ed381f8cdeaaae4bd6778adcb6865c
https://git.kernel.org/stable/c/ca018c19e0ba38975e5ddc3ef8117d5b734313aa