Description
In the Linux kernel, the following vulnerability has been resolved:

NFSv4.1: fix layout segment leak on the pnfs_layout_process() forget path

When the server returns a new layout stateid while a valid one is still
held, pnfs_layout_process() calls pnfs_mark_matching_lsegs_return() on
the on-stack free_me list and jumps to out_forget. Segments whose
reference count drops to zero are unlinked from lo->plh_segs and moved
to free_me by mark_lseg_invalid(); for an idle cached segment the layout
header holds the only reference, so this happens on the first decrement.

out_forget never drains free_me -- only the success path calls
pnfs_free_lseg_list().

Commit 814b84971388 ("pNFS/NFSv4: Fix a layout segment leak in
pnfs_layout_process()") added the drain; commit 08bd8dbe8882
("pNFS/NFSv4: Try to return invalid layout in pnfs_layout_process()")
removed it while switching the destination to lo->plh_return_segs, which
is drained elsewhere. Commit fb700ef02676 ("NFSv4.1: Simplify layout
return in pnfs_layout_process()") switched the destination back to
free_me without restoring the drain.

Restore the pnfs_free_lseg_list() call.
Published: 2026-09-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via memory exhaustion
Action: Apply Patch
AI Analysis

Impact

The Linux kernel contains a bug in the NFSv4.1 pNFS layout handling routine, pnfs_layout_process. When a new layout stateid is returned while an older valid stateid remains, the code attempts to move invalidated layout segments into a temporary free_me list. However, the failure path that normally drains this list is missing, so the segments stay allocated and continue to grow. The accumulated memory consumption can eventually exhaust kernel memory, destabilize the server, or cause a crash. This is a resource exhaustion flaw (CWE‑772).

Affected Systems

The issue exists in any Linux kernel that compiles an NFSv4.1 server without the commit that restores the pnfs_free_lseg_list drain. Any distribution shipping an older kernel or a custom kernel that has not incorporated that patch is impacted. No specific version numbers are given, so all kernels before the patch are vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1% shows a very low but non‑zero chance of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can trigger the memory leak by sending many layout state transition requests from an untrusted NFS client over the network; local privilege escalation is not required. Based on the description, it is inferred that this can be achieved remotely. Because the flaw can be exercised remotely, the potential impact is higher in exposed NFS servers.

Generated by OpenCVE AI on September 15, 2026 at 20:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that includes the commit restoring the pnfs_free_lseg_list drain (e.g., the patch series referenced in the CVE description).
  • If a kernel update cannot be applied immediately, disable the pNFS layout feature in the NFSv4.1 server configuration to avoid executing the vulnerable code path until a patch is available.
  • Monitor server memory usage and layout‑segment counters and configure alerts for abnormal growth that may indicate the leak remains active.

Generated by OpenCVE AI on September 15, 2026 at 20:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: NFSv4.1: fix layout segment leak on the pnfs_layout_process() forget path When the server returns a new layout stateid while a valid one is still held, pnfs_layout_process() calls pnfs_mark_matching_lsegs_return() on the on-stack free_me list and jumps to out_forget. Segments whose reference count drops to zero are unlinked from lo->plh_segs and moved to free_me by mark_lseg_invalid(); for an idle cached segment the layout header holds the only reference, so this happens on the first decrement. out_forget never drains free_me -- only the success path calls pnfs_free_lseg_list(). Commit 814b84971388 ("pNFS/NFSv4: Fix a layout segment leak in pnfs_layout_process()") added the drain; commit 08bd8dbe8882 ("pNFS/NFSv4: Try to return invalid layout in pnfs_layout_process()") removed it while switching the destination to lo->plh_return_segs, which is drained elsewhere. Commit fb700ef02676 ("NFSv4.1: Simplify layout return in pnfs_layout_process()") switched the destination back to free_me without restoring the drain. Restore the pnfs_free_lseg_list() call.
Title NFSv4.1: fix layout segment leak on the pnfs_layout_process() forget path
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:02:09.617Z

Reserved: 2026-09-11T19:38:34.751Z

Link: CVE-2026-89710

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:58.380

Modified: 2026-09-14T13:19:20.800

Link: CVE-2026-89710

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:25Z

Links: CVE-2026-89710 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:45:20Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime