Improper resource shutdown or release in Linux kernel - CVE-2026-89668
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local privileged user to leave orphan debugfs files with stale file-operation pointers into freed module text.
The vulnerability exists due to improper cleanup in the nfsd initialization routine when nfsd4_init_slabs() fails after debugfs initialization. A local privileged user can trigger the affected initialization failure to leave orphan debugfs files with stale file-operation pointers into freed module text.