SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-89683

UNKNOWN · CVSS N/A EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's NFS server, specifically in the handling of dentry references during filehandle lookups for V4ROOT exports. An attacker can exploit this flaw by crafting an NFSv3 filehandle, leading to a memory leak that could degrade system performance or stability over time. System administrators and security teams managing Linux environments with NFS services should prioritize this issue to mitigate potential impacts.

CVE
CVE-2026-89683
Severity
UNKNOWN
CVSS
N/A
EPSS
0.18%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix dentry ref leak on V4ROOT export filehandle lookup nfsd_set_fh_dentry() leaks the dentry reference from exportfs_decode_fh_raw() when the NFS3_FHSIZE or NFS_FHSIZE switch cases detect NFSEXP_V4ROOT and goto out. The out: label calls exp_put() but never dput(dentry), and fhp->fh_dentry was never assigned so fh_put() cannot compensate. A crafted NFSv3 filehandle targeting a V4ROOT export's fsid triggers the leak on every request.