Description
In the Linux kernel, the following vulnerability has been resolved:

nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref

When CONFIG_NFSD_V4_2_INTER_SSC is enabled, nfsd4_putfh() can return
success with fh_dentry and fh_export both NULL if fh_verify() returns
nfserr_stale and putfh->no_verify is true. The NFSD4_FH_FOREIGN flag
is set, but the compound dispatch loop only uses this flag to bypass
the nfserr_nofilehandle check -- it does not prevent subsequent ops
from running with a NULL fh_dentry.

A remote client can exploit this by crafting a COMPOUND that includes
an inter-SSC COPY (which causes check_if_stalefh_allowed() to set
no_verify=true on the saved PUTFH) with an additional op inserted
between the source PUTFH and SAVEFH. For example, SETATTR calls
fh_want_write() which dereferences fh_export->ex_path.mnt without
calling fh_verify() first, causing a NULL pointer dereference in the
nfsd kthread.

Fix this by gating the dispatch loop: when NFSD4_FH_FOREIGN is set
and fh_dentry is NULL, only OP_SAVEFH (needed for the inter-SSC flow)
and ops with ALLOWED_WITHOUT_FH (which don't need a resolved
filehandle) may proceed. All other ops receive nfserr_stale, per
RFC 7862 Section 15.2.3 which specifies that foreign filehandle
validation is deferred to the consuming operation and NFS4ERR_STALE
returned at that point.
Published: 2026-09-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Kernel Crash
Action: Immediate Patch
AI Analysis

Impact

A NULL pointer dereference occurs in the Linux NFSv4 server (nfsd) when a client carefully crafts a COMPOUND request that creates a foreign filehandle with NULL references and then performs a non‑SAVEFH operation such as SETATTR. The kernel does not verify the filehandle before dereferencing it, causing the nfsd kernel thread to crash and potentially leading to a system reboot. This issue is a classic CWE‑476 NULL Pointer Dereference triggered by insufficient input validation.

Affected Systems

All Linux kernel builds that enable CONFIG_NFSD_V4_2_INTER_SSC are impacted. The advisory does not specify a particular release, so any distribution kernel that includes this configuration without the applied fix is vulnerable. The vulnerability resides in the NFSv4 server (nfsd) module of the Linux kernel.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity surface; the EPSS score is < 1%, reflecting a very low yet non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker who can construct a remote COMPOUND request that includes an inter‑SSC COPY followed by a non‑SAVEFH operation can trigger a null‑pointer dereference in the nfsd kernel thread, leading to a crash of the NFS service and a potential denial of service to users relying on NFS.

Generated by OpenCVE AI on September 15, 2026 at 19:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the commit which guards the dispatch loop for foreign filehandles.
  • If inter‑SSC filehandles are not required, disable CONFIG_NFSD_V4_2_INTER_SSC in the kernel configuration.
  • After applying the patch or reconfiguration, restart the NFS service to load the updated module.

Generated by OpenCVE AI on September 15, 2026 at 19:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Sat, 12 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref When CONFIG_NFSD_V4_2_INTER_SSC is enabled, nfsd4_putfh() can return success with fh_dentry and fh_export both NULL if fh_verify() returns nfserr_stale and putfh->no_verify is true. The NFSD4_FH_FOREIGN flag is set, but the compound dispatch loop only uses this flag to bypass the nfserr_nofilehandle check -- it does not prevent subsequent ops from running with a NULL fh_dentry. A remote client can exploit this by crafting a COMPOUND that includes an inter-SSC COPY (which causes check_if_stalefh_allowed() to set no_verify=true on the saved PUTFH) with an additional op inserted between the source PUTFH and SAVEFH. For example, SETATTR calls fh_want_write() which dereferences fh_export->ex_path.mnt without calling fh_verify() first, causing a NULL pointer dereference in the nfsd kthread. Fix this by gating the dispatch loop: when NFSD4_FH_FOREIGN is set and fh_dentry is NULL, only OP_SAVEFH (needed for the inter-SSC flow) and ops with ALLOWED_WITHOUT_FH (which don't need a resolved filehandle) may proceed. All other ops receive nfserr_stale, per RFC 7862 Section 15.2.3 which specifies that foreign filehandle validation is deferred to the consuming operation and NFS4ERR_STALE returned at that point.
Title nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:02:03.192Z

Reserved: 2026-09-11T19:38:34.750Z

Link: CVE-2026-89696

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:56.717

Modified: 2026-09-14T13:19:19.897

Link: CVE-2026-89696

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:46:15Z

Links: CVE-2026-89696 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:00:08Z

Weaknesses