Answer in brief
CVE-2026-89707 records a Unknown severity vulnerability in nfsd: release path refs on follow_down() error. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=cc53ce53c86924bfe98a12ea20b7465038a08792 <194316df81263519156ebe714c4a286bee00e5be || >=cc53ce53c86924bfe98a12ea20b7465038a08792 <467d56fd3ff57447a790c6dc3ede2d02a947d224 || >=cc53ce53c86924bfe98a12ea20b7465038a08792 <2bc4343308d85ee4e0dd3877b384306c96f114c2 || >=cc53ce53c86924bfe98a12ea20b7465038a08792 <6cba08dc1922140d260cfeb30bbda4ee1bf869d8 | 194316df81263519156ebe714c4a286bee00e5be, 467d56fd3ff57447a790c6dc3ede2d02a947d224, 2bc4343308d85ee4e0dd3877b384306c96f114c2, 6cba08dc1922140d260cfeb30bbda4ee1bf869d8 |
| Linux/Linuxgeneric | 2.6.38 | Not reported |
Published upstream
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 11, 2026
In the Linux kernel, the following vulnerability has been resolved: nfsd: release path refs on follow_down() error nfsd_cross_mnt() initializes a local struct path with mntget() and dget() before calling follow_down(). On a negative return the error arm jumps to out without releasing those references: err = follow_down(&path, follow_flags); if (err < 0) goto out; follow_down() never drops the caller's entry-time refs on any error sub-case; for example a pre-cross d_manage() failure leaves path untouched, so the mntget()/dget() taken on entry survive the call. Every other early-exit arm in nfsd_cross_mnt() (other-namespace return, IS_ERR(exp2), and the success tail after the swap) already calls path_put(&path); the err < 0 arm is the lone omission. The leak inflates mnt_count and d_count on each failed cross-mount, blocking umount and pinning dentries against the shrinker, and is reachable by any authenticated NFS client through nfsd_lookup_dentry or the NFSv4 READDIR encode path. Fix by calling path_put(&path) before the goto out in the err < 0 arm so the entry-time refs are released on all follow_down() error returns.
Quoted source text, attributed separately from HOL analysis.