Missing Release of Resource after Effective Lifetime in Linux kernel - CVE-2026-89707
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper resource release in nfsd_cross_mnt() when handling NFS requests that result in follow_down() errors. A remote user can send NFS requests that trigger failed cross-mount operations to cause a denial of service.
The issue is reachable through nfsd_lookup_dentry or NFSv4 READDIR encoding.