Description
In the Linux kernel, the following vulnerability has been resolved:

NFS: fix delegation_hash_table leak when nfs4_server_common_setup() fails

nfs4_server_common_setup() allocates server->delegation_hash_table
first, but server->destroy - the only path that frees the table via
nfs4_destroy_server() - is not assigned until the very end of the
function. If any intermediate step fails (the is_ds_only_client()
check, nfs4_init_session(), nfs4_get_rootfh(), or nfs_probe_server()),
the function returns with server->destroy still NULL, so the caller's
nfs_free_server() skips the destroy callback and the hash table is
leaked (4 KiB per attempt with the default delegation watermark).

This is trivially reachable from userspace: every failed NFSv4 mount
leaks one allocation. A client that persistently retries a mount that
cannot succeed leaks kernel memory without bound. Observed in
production where a Longhorn backup poller retried mount.nfs4 against
an NFSv3-only server roughly 10 times per second, leaking ~3.4 GiB of
unreclaimable slab (kmalloc-rnd-13-4k) per day; the node accumulated
12 GiB of leaked slab before the source was identified via the
kmem:kmalloc tracepoint (call_site=nfs4_delegation_hash_alloc).

Reproducer:

# server exports NFSv3 only (or export path absent for v4)
while :; do mount -t nfs4 <server>:/missing /mnt; done
# watch SUnreclaim in /proc/meminfo grow 4 KiB per iteration

Free the table on the error paths between the allocation and the
assignment of server->destroy.
Published: 2026-09-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Kernel Memory Leak
Action: Apply Patch
AI Analysis

Impact

The vulnerability stems from a missing cleanup path in the Linux kernel’s NFSv4 server initialization. When nfs4_server_common_setup allocates a delegation hash table, it delays assigning the destroy callback until the function completes. If any intermediate check fails, the destroy callback remains null, causing the hash table memory leak 4 KiB of unchanged kernel memory. A client that repeats a failed mount can progressively exhaust all unreclaimable slab memory. In a real‑world scenario against an NFSv3‑only server, the leak can reach several gigabytes per day, potentially exhausting available kernel memory and degrading service reliability.

Affected Systems

All Linux kernels with NFS support are affected before the patch commits linked in the advisory; the fix is included in recent kernel releases. The vulnerability is present in Linux distributions that ship a recent kernel with NFS stack compiled. It is reachable from any userspace NFS client when a mount request fails, such as trying to mount an unexported path or against an NFSv3‑only server.

Risk and Exploitability

The CVSS v3 score of 7.5 indicates high severity, and the EPSS score is < 1%, indicating a very low probability of exploitation. The flaw is not listed in CISA’s KEV catalog. The attack vector is trivially reachable from any NFSv4 mount; a malicious or misconfigured client that repeatedly attempts mounts against an NFSv3‑only server or a nonexistent export exploitation and the potentially catastrophic service degradation, the overall risk is significant.

Generated by OpenCVE AI on September 15, 2026 at 19:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the NFSv4 delegation hash table cleanup patch.
  • Disable or limit automatic mount retries on client systems to prevent repetitive failed mount attempts.
  • Modify automated backup or monitoring scripts that might be issuing repeated mount commands, ensuring they stop after a reasonable number of failures.
  • Monitor kernel memory usage via /proc/meminfo, particularly the SUnreclaim field, and set alerts for abnormal growth.

Generated by OpenCVE AI on September 15, 2026 at 19:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: NFS: fix delegation_hash_table leak when nfs4_server_common_setup() fails nfs4_server_common_setup() allocates server->delegation_hash_table first, but server->destroy - the only path that frees the table via nfs4_destroy_server() - is not assigned until the very end of the function. If any intermediate step fails (the is_ds_only_client() check, nfs4_init_session(), nfs4_get_rootfh(), or nfs_probe_server()), the function returns with server->destroy still NULL, so the caller's nfs_free_server() skips the destroy callback and the hash table is leaked (4 KiB per attempt with the default delegation watermark). This is trivially reachable from userspace: every failed NFSv4 mount leaks one allocation. A client that persistently retries a mount that cannot succeed leaks kernel memory without bound. Observed in production where a Longhorn backup poller retried mount.nfs4 against an NFSv3-only server roughly 10 times per second, leaking ~3.4 GiB of unreclaimable slab (kmalloc-rnd-13-4k) per day; the node accumulated 12 GiB of leaked slab before the source was identified via the kmem:kmalloc tracepoint (call_site=nfs4_delegation_hash_alloc). Reproducer: # server exports NFSv3 only (or export path absent for v4) while :; do mount -t nfs4 <server>:/missing /mnt; done # watch SUnreclaim in /proc/meminfo grow 4 KiB per iteration Free the table on the error paths between the allocation and the assignment of server->destroy.
Title NFS: fix delegation_hash_table leak when nfs4_server_common_setup() fails
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:46:28.476Z

Reserved: 2026-09-11T19:38:34.751Z

Link: CVE-2026-89714

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:58.873

Modified: 2026-09-11T20:19:58.873

Link: CVE-2026-89714

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:28Z

Links: CVE-2026-89714 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:30:12Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime