Description
In the Linux kernel, the following vulnerability has been resolved:

nfsd: release path refs on follow_down() error

nfsd_cross_mnt() initializes a local struct path with mntget() and
dget() before calling follow_down(). On a negative return the error
arm jumps to out without releasing those references:

err = follow_down(&path, follow_flags);
if (err < 0)
goto out;

follow_down() never drops the caller's entry-time refs on any error
sub-case; for example a pre-cross d_manage() failure leaves path
untouched, so the mntget()/dget() taken on entry survive the call.

Every other early-exit arm in nfsd_cross_mnt() (other-namespace
return, IS_ERR(exp2), and the success tail after the swap) already
calls path_put(&path); the err < 0 arm is the lone omission. The
leak inflates mnt_count and d_count on each failed cross-mount,
blocking umount and pinning dentries against the shrinker, and is
reachable by any authenticated NFS client through nfsd_lookup_dentry
or the NFSv4 READDIR encode path.

Fix by calling path_put(&path) before the goto out in the err < 0
arm so the entry-time refs are released on all follow_down() error
returns.
Published: 2026-09-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (resource exhaustion)
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is a missing reference release in the Linux kernel’s NFS server code, representing a CWE‑911: Improper Release of a Resource after Effective Lifetime. The bug causes mntget() and dget() references to remain unreleased when follow_down() fails. As a result, mnt_count and d_count continue to increase for each failed cross‑mount, pinning dentries and blocking unmounts, which can lead to denial of service.

Affected Systems

The vulnerability affects all Linux kernel versions that include the buggy nfsd_cross_mnt implementation without the in the core kernel source, every distribution running a kernel compiled before the commit that introduces path_put(&path) before the error return is vulnerable. Any authenticated NFS client can trigger the flaw via nfsd_lookup_dentry or the NFSv4 READDIR encode path.

Risk and Exploitability

The risk is moderate to high, as the flaw can lead to resource exhaustion and denial of service by preventing successful unmounts. The CVSS score of 7.5 reflects this high severity. The EPSS score is below not listed in the CISA KEV catalog, indicating a comparatively low likelihood of widespread exploitation. Nevertheless, an authenticated NFS client can trigger the flaw by making a request that causes follow_down to fail, for example through nfsd_lookup_dentry or an NFSv4 READDIR encode path. Such an attacker can repeatedly invoke the error path, each time leaking mntget() and dget() references, inflating mnt_count and d_count until the system becomes unable to unmount filesystems or shrink dentries, resulting in a denial of service. This attack vector requires network access to the NFS server and valid client credentials.

Generated by OpenCVE AI on September 15, 2026 at 19:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest stable Linux kernel release that includes the path_put(&path) fix for nfsd_cross_mnt or apply the specific patch commit 194316df8…
  • Temporarily disable the NFS service or block NFS client traffic on the server until the kernel is updated, to prevent exploitation during the vulnerable window.
  • After applying the patch, monitor kernel logs and system metrics for elevated mnt_count/d_count values and verify that unmount and datadir shrink operations function normally.

Generated by OpenCVE AI on September 15, 2026 at 19:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Sat, 12 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401
CWE-668

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-911
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Sat, 12 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401
CWE-668

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nfsd: release path refs on follow_down() error nfsd_cross_mnt() initializes a local struct path with mntget() and dget() before calling follow_down(). On a negative return the error arm jumps to out without releasing those references: err = follow_down(&path, follow_flags); if (err < 0) goto out; follow_down() never drops the caller's entry-time refs on any error sub-case; for example a pre-cross d_manage() failure leaves path untouched, so the mntget()/dget() taken on entry survive the call. Every other early-exit arm in nfsd_cross_mnt() (other-namespace return, IS_ERR(exp2), and the success tail after the swap) already calls path_put(&path); the err < 0 arm is the lone omission. The leak inflates mnt_count and d_count on each failed cross-mount, blocking umount and pinning dentries against the shrinker, and is reachable by any authenticated NFS client through nfsd_lookup_dentry or the NFSv4 READDIR encode path. Fix by calling path_put(&path) before the goto out in the err < 0 arm so the entry-time refs are released on all follow_down() error returns.
Title nfsd: release path refs on follow_down() error
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:02:08.548Z

Reserved: 2026-09-11T19:38:34.751Z

Link: CVE-2026-89707

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:58.017

Modified: 2026-09-14T13:19:20.690

Link: CVE-2026-89707

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:23Z

Links: CVE-2026-89707 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:45:07Z

Weaknesses
  • CWE-911

    Improper Update of Reference Count