Description
In the Linux kernel, the following vulnerability has been resolved:

nfsd: move nfsd_debugfs_init() after nfsd4_init_slabs() in init_nfsd()

nfsd_debugfs_init() runs before nfsd4_init_slabs() in init_nfsd().
If the slab allocation fails, the bare "return retval" bypasses
nfsd_debugfs_exit(), leaving orphan debugfs files with stale fops
pointers into the freed module text.

Move nfsd_debugfs_init() to after the slab init succeeds, so the
early return has no debugfs state to clean up.

Since debugfs is now the more recently initialized of the two, also
update the unwind paths to match reverse-initialization (LIFO) order:
run nfsd_debugfs_exit() before nfsd4_free_slabs() in both the
init_nfsd() error path and exit_nfsd(). The nfsd debugfs files only
reference module-global state and have no dependency on the slab
caches, so that reordering is a cleanup with no functional change.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Crash via DebugFS
Action: Apply Patch
AI Analysis

Impact

The Linux kernel’s NFS daemon initialization sequence had a flaw that caused debugfs entries to be created before the allocation of necessary slab caches. When the slab allocation failed, the early return from init_nfsd() skipped cleanup, leaving orphaned debugfs files that referenced function pointers in freed kernel text. Subsequent interaction with these stale pointers can trigger a kernel panic, resulting in a local denial‑of‑service.

Affected Systems

All Linux kernel builds that ship the stock NFS server and have not merged the commit which moves nfsd are vulnerable. The affected product is effectively the Linux kernel as a whole; specific version bounds are not listed, so any distribution kernel that predates the patch should be considered at risk.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity vulnerability that can lead to a kernel crash. The EPSS score is less than 1% and the vulnerability is not listed in CISA’s KEV catalog, suggesting it is not widely exploited. The flaw causes orphaned debugfs files with stale function pointers when slab allocation fails during NFS trigger a kernel panic, though the required platform state or permissions to trigger the crash are not explicitly documented in the CVE description. Prompt patching or containment of debugfs access mitigates the potential impact.

Generated by OpenCVE AI on September 15, 2026 at 20:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install a kernel that contains the commit reordering debugfs initialization (for example, update to a kernel that includes commit d67095fe444401 version).
  • If a kernel upgrade cannot be performed immediately, disable or unmount the debugfs filesystem to prevent access to orphaned entries.
  • If the NFS daemon is not required, stop and disable the nfsd service.
  • Reboot the system after applying the remaining orphaned debugfs entries and ensure kernel stability.

Generated by OpenCVE AI on September 15, 2026 at 20:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nfsd: move nfsd_debugfs_init() after nfsd4_init_slabs() in init_nfsd() nfsd_debugfs_init() runs before nfsd4_init_slabs() in init_nfsd(). If the slab allocation fails, the bare "return retval" bypasses nfsd_debugfs_exit(), leaving orphan debugfs files with stale fops pointers into the freed module text. Move nfsd_debugfs_init() to after the slab init succeeds, so the early return has no debugfs state to clean up. Since debugfs is now the more recently initialized of the two, also update the unwind paths to match reverse-initialization (LIFO) order: run nfsd_debugfs_exit() before nfsd4_free_slabs() in both the init_nfsd() error path and exit_nfsd(). The nfsd debugfs files only reference module-global state and have no dependency on the slab caches, so that reordering is a cleanup with no functional change.
Title nfsd: move nfsd_debugfs_init() after nfsd4_init_slabs() in init_nfsd()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:32:50.192Z

Reserved: 2026-09-11T19:38:34.745Z

Link: CVE-2026-89668

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:53.290

Modified: 2026-09-13T07:17:32.423

Link: CVE-2026-89668

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:45:54Z

Links: CVE-2026-89668 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:30:10Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference