Description
In the Linux kernel, the following vulnerability has been resolved:

nfsd: ensure nfsd_file_do_acquire() does not use a non-opened file

->atomic_open is permitted to return success without actually opening
the file. It indicates this by calling finish_no_open().
This means dentry_create() can return a file which hasn't been opened.
This is extremely unlikely as ->atomic_open handlers typically
use finish_no_open() only for already existing files, and dentry_create()
isn't called in that case, and the parent being locked should prevent
races.

However out of an abundance of caution it seems wise to teach nfsd to
only use the file returned by dentry_create() if FMODE_OPENED is set,
indicating that it has in fact been opened.
Published: 2026-09-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Potential data integrity compromise via NFS file handling
Action: Patch now
AI Analysis

Impact

A flaw in the Linux kernel’s NFS server allows the function nfsd_file_do_acquire() to operate on a file returned by dentry_create() that might not have actually been opened. This mis‑use of an uninitialized resource (CWE-908) can lead the NFS server to perform unexpected file operations, potentially causing data corruption or unauthorized access to files by clients. The vulnerability does not provide remote code execution but can impact the confidentiality and integrity of data stored on the server.

Affected Systems

The issue affects all Linux kernel builds that include the buggy nfsd implementation and predates the patch that checks the FMODE_OPENED flag. No specific kernel versions are enumerated in the CVE data, so every kernel compiled from the public source before the referenced commit is considered vulnerable.

Risk and Exploitability

With a CVSS score of 7.5 the flaw has high severity, yet the EPSS score of <1% and the fact that the weakness relies on a rarely‑occurring race condition suggest a low to moderate likelihood of exploitation. The attack would require a malicious or compromised NFS client that can request a file in a way that forces nfsd_file_do_acquire() to work with an unopened file. The flaw is not listed in the CISA KEV catalog and is unlikely to be active in production unless the kernel is unpatched and exposed to untrusted network clients.

Generated by OpenCVE AI on September 15, 2026 at 20:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes commits 5859cc01fee06a2cd7458905a9593082fbab06e1 and a95a1cffacd0203100297001719160160f443dd6
  • Restart the NFS service or reboot the system to load the patched kernel
  • If an immediate kernel upgrade is not possible, limit N disabling the NFS service temporarily

Generated by OpenCVE AI on September 15, 2026 at 20:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-908
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nfsd: ensure nfsd_file_do_acquire() does not use a non-opened file ->atomic_open is permitted to return success without actually opening the file. It indicates this by calling finish_no_open(). This means dentry_create() can return a file which hasn't been opened. This is extremely unlikely as ->atomic_open handlers typically use finish_no_open() only for already existing files, and dentry_create() isn't called in that case, and the parent being locked should prevent races. However out of an abundance of caution it seems wise to teach nfsd to only use the file returned by dentry_create() if FMODE_OPENED is set, indicating that it has in fact been opened.
Title nfsd: ensure nfsd_file_do_acquire() does not use a non-opened file
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:33:11.048Z

Reserved: 2026-09-11T19:38:34.749Z

Link: CVE-2026-89687

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:55.663

Modified: 2026-09-13T07:17:34.493

Link: CVE-2026-89687

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:08Z

Links: CVE-2026-89687 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:30:10Z

Weaknesses
  • CWE-908

    Use of Uninitialized Resource