Description
In the Linux kernel, the following vulnerability has been resolved:

nfsd: fix dentry ref leak on V4ROOT export filehandle lookup

nfsd_set_fh_dentry() leaks the dentry reference from
exportfs_decode_fh_raw() when the NFS3_FHSIZE or NFS_FHSIZE
switch cases detect NFSEXP_V4ROOT and goto out. The out: label
calls exp_put() but never dput(dentry), and fhp->fh_dentry was
never assigned so fh_put() cannot compensate.

A crafted NFSv3 filehandle targeting a V4ROOT export's fsid
triggers the leak on every request.
Published: 2026-09-11
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Resource Leak
Action: Apply Patch
AI Analysis

Impact

The vulnerability lies in nfsd_set_fh_dentry, which inadvertently retains a dentry reference when processing an NFSv3 filehandle that references a V4ROOT export. This leaks kernel memory for every request. The weakness is recognized as a resource leak, aligning with CWE-911.

Affected Systems

The flaw is present in the Linux kernel’s NFS daemon, so any Linux machine running a kernel build before the patch is at risk. No specific kernel version range is supplied; therefore all exposed Linux installations are potentially vulnerable. The patch targets the exportfs_decode_fh_raw and nfsd_set_fh_dentry code paths used for NFSv3 filehandle processing.

Risk and Exploitability

The CVSS score is 5.9, and the EPSS score is < 1%, indicating a very low exploitation probability. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known large‑scale campaigns. Based on the description, it is inferred that an attacker could craft an NFSv3 filehandle targeting a V4ROOT export's fsid; a remote client would then repeatedly invoke lookups that trigger the leak.

Generated by OpenCVE AI on September 15, 2026 at 20:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official kernel patch to update the Linux kernel to a version that includes the NFSd fix.
  • Disable or restrict NFSv3 export access to V4ROOT exports so the vulnerable code path cannot be exercised.
  • Monitor system memory usage for signs of sustained leaks and isolate NFS services within a protected network segment.

Generated by OpenCVE AI on September 15, 2026 at 20:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-911
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nfsd: fix dentry ref leak on V4ROOT export filehandle lookup nfsd_set_fh_dentry() leaks the dentry reference from exportfs_decode_fh_raw() when the NFS3_FHSIZE or NFS_FHSIZE switch cases detect NFSEXP_V4ROOT and goto out. The out: label calls exp_put() but never dput(dentry), and fhp->fh_dentry was never assigned so fh_put() cannot compensate. A crafted NFSv3 filehandle targeting a V4ROOT export's fsid triggers the leak on every request.
Title nfsd: fix dentry ref leak on V4ROOT export filehandle lookup
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:46:05.635Z

Reserved: 2026-09-11T19:38:34.748Z

Link: CVE-2026-89683

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:55.173

Modified: 2026-09-11T20:19:55.173

Link: CVE-2026-89683

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:05Z

Links: CVE-2026-89683 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:45:20Z

Weaknesses
  • CWE-911

    Improper Update of Reference Count