Description
In the Linux kernel, the following vulnerability has been resolved:

nfsd: fix possible fh_compose of wrong dentry in nfsd4_create_file()

dentry_create() can hypothetically provide a different dentry than the
one passed in. This could happen, for example, if the exported
filesystem is NFS, and the server returned to OPEN a filehandle which
matched a directory that was already in the dcache. Clearly this would
not be expected!

If this were to happen the dentry (child) that was already stored in
resfhp could be freed and later dereferenced.

We shouldn't call fh_compose() until we are certain that we have the
final dentry, so this patch moved the fh_compose() call to two places:
one for the case where the target already exists, and one after
dentry_create() where it was created.
Published: 2026-09-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption potentially leading to privilege escalation
Action: Upgrade Kernel
AI Analysis

Impact

The flaw arises in the NFSv4 server’s file creation logic when a filehandle is composed with a directory entry that does not match the intended target. The bug can cause a dentry that is still referenced to be freed and later dereferenced, leading to memory corruption in kernel space. This corruption could crash the kernel or be exploited to gain elevated privileges. It is an improper reference handling weakness, identified as CWE-825.

Affected Systems

Linux systems with kernels that implement the NFSv4 server prior to the recent fixes are affected. The issue applies to all distributions and kernel versions that have not yet incorporated the commit that relocates the fh_compose call. Any system exposing or using the NFSv4 protocol is therefore at risk.

Risk and Exploitability

The CVSS score of 9.8 indicates a high severity flaw. The EPSS score of less than 1% suggests that no widespread exploitation is currently observed. It is not listed in CISA’s KEV catalog. The likely attack vector is remote over the NFSv4 protocol, though local privilege escalation cannot be excluded. An attacker would need to craft an NFSv4 CREATE request that triggers the faulty dentry handling. No public exploits have been disclosed.

Generated by OpenCVE AI on September 15, 2026 at 20:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version that includes the fh_compose fix (e.g., after commit 033e7837 or 3e2c7936).
  • If an immediate kernel upgrade is not possible, disable or stop NFSv4 server and/or client services to eliminate the attack surface.
  • Restrict NFSv4 traffic to trusted hosts using firewall or ACL rules until the kernel can be patched.

Generated by OpenCVE AI on September 15, 2026 at 20:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H'}

threat_severity

Important


Sat, 12 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nfsd: fix possible fh_compose of wrong dentry in nfsd4_create_file() dentry_create() can hypothetically provide a different dentry than the one passed in. This could happen, for example, if the exported filesystem is NFS, and the server returned to OPEN a filehandle which matched a directory that was already in the dcache. Clearly this would not be expected! If this were to happen the dentry (child) that was already stored in resfhp could be freed and later dereferenced. We shouldn't call fh_compose() until we are certain that we have the final dentry, so this patch moved the fh_compose() call to two places: one for the case where the target already exists, and one after dentry_create() where it was created.
Title nfsd: fix possible fh_compose of wrong dentry in nfsd4_create_file()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:32:59.920Z

Reserved: 2026-09-11T19:38:34.747Z

Link: CVE-2026-89677

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:54.393

Modified: 2026-09-13T07:17:33.423

Link: CVE-2026-89677

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:46:01Z

Links: CVE-2026-89677 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:30:10Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference