CVE-2026-89715

Summary

In the Linux kernel, the following vulnerability has been resolved:

NFS/localio: fix ref leak on nfs_uuid_add_file failure

When nfs_uuid_add_file() races with nfs_uuid_put() tearing down uuid->net, it returns -ENXIO without publishing nfl->nfs_uuid via rcu_assign_pointer(). nfs_open_local_fh() then enters its error branch and only releases the slot's file ref and its paired net ref plus its own entry-time net ref, while the close path is a no-op:

nfs_close_local_fh()
  nfs_uuid = rcu_dereference(nfl->nfs_uuid);
  if (!nfs_uuid) { rcu_read_unlock(); return; }  /* always */

nfsd_open_local_fh() returns localio holding a caller-owned +1 nfsd_file reference (from nfsd_file_get() after nfsd_file_acquire_local()) and an entry-time nfsd_net reference (from its first nfsd_net_try_get()) embedded as nf->nf_net. Both are leaked on the failure path, pinning one nfsd_file (and the underlying struct file, dentry, inode) and one nfsd_net_ref per occurrence, which blocks nfsd_net and netns teardown.

Fix by releasing the caller-owned file ref and its net ref through the existing helper, using a stack-local RCU pointer so the helper can xchg it out, then returning -ENXIO so callers do not dereference a localio whose slot has been cleared:

struct nfsd_file __rcu *tmp = RCU_INITIALIZER(localio);

nfs_to_nfsd_file_put_local(pnf);
nfs_to_nfsd_file_put_local(&tmp);
localio = ERR_PTR(-ENXIO);

The trailing nfs_to_nfsd_net_put(net) continues to release the outer net ref, so all three nfsd_net_try_get() increments are balanced on the error branch.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxfdd015de767977f21892329af5e12276eb80375f < 5215e734bf7cba18237155f8cb2a0accb60ca339affected
LinuxLinuxfdd015de767977f21892329af5e12276eb80375f < 9f59b05423ed381f8cdeaaae4bd6778adcb6865caffected
LinuxLinuxfdd015de767977f21892329af5e12276eb80375f < ca018c19e0ba38975e5ddc3ef8117d5b734313aaaffected
LinuxLinux55735dc5a0ee0c0fc14cb51e005eae862906a410affected
LinuxLinux7cac8a129fc53497f9ee5d66fca55a245d009b97affected
LinuxLinux6.15.10 < 6.16affected
LinuxLinux6.16.1 < 6.17affected
LinuxLinux6.17affected
LinuxLinux0 < 6.17unaffected
LinuxLinux6.18.50 <= 6.18.*unaffected
LinuxLinux7.2.4 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References