Improper input validation in Linux kernel - CVE-2026-89687
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause nfsd to use a file that has not been opened.
The vulnerability exists due to improper validation of file open state in nfsd_file_do_acquire() when acquiring a file returned by dentry_create(). A remote attacker can trigger nfsd to use a file that has not been opened.
The condition requires atomic_open to report success without opening the file.