Description
In the Linux kernel, the following vulnerability has been resolved:

NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check

The header for commit e75b23f9e323 ("nfsd: check d_can_lookup in
fh_verify of directories") details the assumption that justified
adding the WARN_ON_ONCE to nfsd_mode_check(), that assumption is
invalid (in the case of NFS reexport).

When NFSD exports an NFS filesystem it is very possible for
nfsd_mode_check() to encounter a @dentry that doesn't have
i_op->lookup (see nfs_fhget()'s NFS_ATTR_FATTR_MOUNTPOINT and
NFS_ATTR_FATTR_V4_REFERRAL handling, and d_flags_for_inode()).

So remove nfsd_mode_check()'s WARN_ON_ONCE(). The nfserr_notdir
return on that branch must stay. It guards the subsequent
lookup_one_unlocked() -> __lookup_slow() path, which calls
inode->i_op->lookup() with no NULL check, so returning nfserr_notdir
is what keeps a client LOOKUP into such a @dentry from dereferencing
a NULL method pointer.
Published: 2026-09-11
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (kernel crash)
Action: Patch Now
AI Analysis

Impact

The flaw occurs when the NFS server processes a lookup request that references a directory entry lacking a lookup method. This missing method can trigger a null‑pointer dereference in the nfserr_notdir path, leading the kernel to crash. The weakness identified is a null pointer dereference (CWE‑476). The crash causes a sudden loss of service for any client whose request reaches the vulnerable code path.

Affected Systems

All Linux kernel versions that have not incorporated commit e75b23f9e323 in the NFSD mode‑check logic are affected. This includes the mainline upstream kernel as well as distribution kernels that have not yet applied the patch or an equivalent vendor update. The issue is triggered only when the NFS server exports a filesystem that may be re‑exported, and an NFS client may send a LOOKUP that targets a directory entry without a lookup method.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.2, indicating high severity, but its EPSS score is less than 1 %, reflecting a very low exploitation likelihood in the wild. It is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote via NFS: an attacker only needs the ability to send crafted NFS LOOKUP requests to the affected server. Successful exploitation would cause the kernel to crash, resulting in a denial‑of‑service attack with no direct privilege escalation or data exfiltration potential as per the current data.

Generated by OpenCVE AI on September 15, 2026 at 19:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes commit e75b23f9e323 or the corresponding vendor patch.
  • If a patch cannot be applied immediately, disable or stop the NFSD service to eliminate the vulnerable lookup path until the kernel is updated.
  • Restrict NFS access to trusted clients by enabling strict subtree checks.

Generated by OpenCVE AI on September 15, 2026 at 19:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H'}


Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check The header for commit e75b23f9e323 ("nfsd: check d_can_lookup in fh_verify of directories") details the assumption that justified adding the WARN_ON_ONCE to nfsd_mode_check(), that assumption is invalid (in the case of NFS reexport). When NFSD exports an NFS filesystem it is very possible for nfsd_mode_check() to encounter a @dentry that doesn't have i_op->lookup (see nfs_fhget()'s NFS_ATTR_FATTR_MOUNTPOINT and NFS_ATTR_FATTR_V4_REFERRAL handling, and d_flags_for_inode()). So remove nfsd_mode_check()'s WARN_ON_ONCE(). The nfserr_notdir return on that branch must stay. It guards the subsequent lookup_one_unlocked() -> __lookup_slow() path, which calls inode->i_op->lookup() with no NULL check, so returning nfserr_notdir is what keeps a client LOOKUP into such a @dentry from dereferencing a NULL method pointer.
Title NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:02:10.683Z

Reserved: 2026-09-11T19:38:34.751Z

Link: CVE-2026-89711

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:58.500

Modified: 2026-09-14T13:19:20.930

Link: CVE-2026-89711

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:26Z

Links: CVE-2026-89711 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:30:12Z

Weaknesses