CVE-2026-89680

Source
https://cve.org/CVERecord?id=CVE-2026-89680
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89680.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89680
Downstream
Published
2026-09-11T19:46:03Z
Modified
2026-09-13T03:47:20Z
Summary
nfsd: fix nfsd_file leak on inter-server COPY setup failure
Details

In the Linux kernel, the following vulnerability has been resolved:

nfsd: fix nfsd_file leak on inter-server COPY setup failure

When nfsd4_setup_inter_ssc() fails, nfsd4_copy() returns nfserr_offload_denied directly, bypassing the out: label where release_copy_files() would drop the nf_dst reference taken by nfs4_preprocess_stateid_op(). Each failed inter-server COPY leaks one nfsd_file, pinning file/inode/dentry/vfsmount.

Fix by setting status and jumping to out: instead of returning directly.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89680.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ce0887ac96d35c7105090e166bb0807dc0a0e838
Fixed
1a6a41b848455bf6ba2c9da2dfb0730e608ce7ab
Fixed
424d5c95108a4809b832cb0a312c61de4aec0078
Fixed
6ed8d6de7ec90c4ba84eb82673058f506e5777fd
Fixed
88a76145451d703eedd867b5989bf73d17340399

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89680.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.6.0
Fixed
6.12.109
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.50
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89680.json"