CVE-2026-89707
In the Linux kernel, the following vulnerability has been resolved: nfsd: release path refs on follow_down() error nfsd_cross_mnt() initia
CVSS
—
Sin CVSS
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 11 sept 2026 · Última mod.: 11 sept 2026
Sin historial EPSS suficiente todavía.
In the Linux kernel, the following vulnerability has been resolved: nfsd: release path refs on follow_down() error nfsd_cross_mnt() initializes a local struct path with mntget() and dget() before calling follow_down(). On a negative return the error arm jumps to out without releasing those references: err = follow_down(&path, follow_flags); if (err < 0) goto out; follow_down() never drops the caller's entry-time refs on any error sub-case; for example a pre-cross d_manage() failure leaves path untouched, so the mntget()/dget() taken on entry survive the call. Every other early-exit arm in nfsd_cross_mnt() (other-namespace return, IS_ERR(exp2), and the success tail after the swap) already calls path_put(&path); the err < 0 arm is the lone omission. The leak inflates mnt_count and d_count on each failed cross-mount, blocking umount and pinning dentries against the shrinker, and is reachable by any authenticated NFS client through nfsd_lookup_dentry or the NFSv4 READDIR encode path. Fix by calling path_put(&path) before the goto out in the err < 0 arm so the entry-time refs are released on all follow_down() error returns.
- git.kernel.orghttps://git.kernel.org/stable/c/194316df81263519156ebe714c4a286bee00e5be
- git.kernel.orghttps://git.kernel.org/stable/c/2bc4343308d85ee4e0dd3877b384306c96f114c2
- git.kernel.orghttps://git.kernel.org/stable/c/467d56fd3ff57447a790c6dc3ede2d02a947d224
- git.kernel.orghttps://git.kernel.org/stable/c/6cba08dc1922140d260cfeb30bbda4ee1bf869d8
Sin CVEs relacionados por CWE o producto.