Description
In the Linux kernel, the following vulnerability has been resolved:

nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache

The shrinker, GC worker, and fsnotify/lease callbacks can unhash an
nfsd_file from the rhashtable and then call
nfsd_file_dispose_list_delayed() to move it to the per-net dispose list.
If nfsd_file_cache_shutdown_net() runs concurrently, its rhashtable walk
misses the already-unhashed file, and its drain of the per-net dispose
list can run before the file has been queued. The file then sits on
the per-net list with no thread to drain it, leaking both the file and
its associated state.

The GC worker and shrinker already hold nfsd_gc_lock while walking the
LRU, but in the original code they release it before calling
nfsd_file_dispose_list_delayed(). The fsnotify/lease path
(nfsd_file_close_inode) has no synchronization at all.

Fix this by:

1. Widening nfsd_gc_lock in both nfsd_file_gc() and nfsd_file_lru_scan()
to cover the nfsd_file_dispose_list_delayed() call.

2. Wrapping nfsd_file_close_inode() in nfsd_gc_lock so that all three
callers of nfsd_file_dispose_list_delayed() hold the lock.

3. Adding a spin_lock/unlock(nfsd_gc_lock) barrier in
nfsd_file_cache_shutdown_net() after the purge, so that any
in-progress disposal has fully completed before the per-net list
is drained.

All operations inside the lock are non-sleeping (rhashtable lookups,
atomic bit/refcount ops, list moves, svc_wake_up), so the spinlock is
appropriate.
Published: 2026-09-11
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Resource exhaustion that may lead to denial of service
Action: Update Kernel
AI Analysis

Impact

The vulnerability resides in the NFS daemon’s handling of file cache cleanup. When a cached NFS file is removed by the shrinker, garbage‑collector worker, or fsnotify callbacks, the file can be unhashed from the reference map and then deferred to a per‑network disposal list. If the net‑shut‑down routine runs concurrently, it may miss the unhashed entry and drain the disposal list before the file has been queued, leaving the file and its associated kernel state stranded. The leaked objects accumulate in memory, potentially exhausting resources and degrading system availability. The weakness is identified as CWE‑772, an unreleased resource cycle.

Affected Systems

The Linux kernel’s NFS daemon component is affected. Any kernel build that does not include the documented fix is vulnerable. No specific version ranges are listed, so all current distribution kernels may need verification.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity. The EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV catalog, suggesting a very low likelihood of exploitation in the wild. This is a kernel‑level flaw that requires either local or privileged access to the NFS daemon; the likely attack vector is local exploitation or compromise of a privileged process. An attacker who can trigger the race condition could cause uncontrolled memory growth and eventual service disruption.

Generated by OpenCVE AI on September 15, 2026 at 20:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the patch which widens the nfsd_gc_lock, wraps nfsd_file_close_inode in that lock, and adds a spin_lock barrier in nfsd_file_cache_shutdown_net().
  • If an updated kernel is not immediately available, temporarily disable the NFS daemon or restrict its file cache size to reduce the chance of a runaway leak.
  • Continuously monitor system memory usage and examine kernel logs for indications of NFS‑abnormal memory growth is observed.

Generated by OpenCVE AI on September 15, 2026 at 20:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 21 Sep 2026 13:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache The shrinker, GC worker, and fsnotify/lease callbacks can unhash an nfsd_file from the rhashtable and then call nfsd_file_dispose_list_delayed() to move it to the per-net dispose list. If nfsd_file_cache_shutdown_net() runs concurrently, its rhashtable walk misses the already-unhashed file, and its drain of the per-net dispose list can run before the file has been queued. The file then sits on the per-net list with no thread to drain it, leaking both the file and its associated state. The GC worker and shrinker already hold nfsd_gc_lock while walking the LRU, but in the original code they release it before calling nfsd_file_dispose_list_delayed(). The fsnotify/lease path (nfsd_file_close_inode) has no synchronization at all. Fix this by: 1. Widening nfsd_gc_lock in both nfsd_file_gc() and nfsd_file_lru_scan() to cover the nfsd_file_dispose_list_delayed() call. 2. Wrapping nfsd_file_close_inode() in nfsd_gc_lock so that all three callers of nfsd_file_dispose_list_delayed() hold the lock. 3. Adding a spin_lock/unlock(nfsd_gc_lock) barrier in nfsd_file_cache_shutdown_net() after the purge, so that any in-progress disposal has fully completed before the per-net list is drained. All operations inside the lock are non-sleeping (rhashtable lookups, atomic bit/refcount ops, list moves, svc_wake_up), so the spinlock is appropriate.
Title nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-21T13:14:42.944Z

Reserved: 2026-09-11T19:38:34.745Z

Link: CVE-2026-89667

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:53.177

Modified: 2026-09-21T14:17:24.830

Link: CVE-2026-89667

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:45:53Z

Links: CVE-2026-89667 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:45:20Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime