CVE-2026-89714

Source
https://cve.org/CVERecord?id=CVE-2026-89714
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89714.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89714
Downstream
Published
2026-09-11T19:46:28Z
Modified
2026-09-13T03:47:20Z
Summary
NFS: fix delegation_hash_table leak when nfs4_server_common_setup() fails
Details

In the Linux kernel, the following vulnerability has been resolved:

NFS: fix delegation_hash_table leak when nfs4_server_common_setup() fails

nfs4_server_common_setup() allocates server->delegation_hash_table first, but server->destroy - the only path that frees the table via nfs4_destroy_server() - is not assigned until the very end of the function. If any intermediate step fails (the is_ds_only_client() check, nfs4_init_session(), nfs4_get_rootfh(), or nfs_probe_server()), the function returns with server->destroy still NULL, so the caller's nfs_free_server() skips the destroy callback and the hash table is leaked (4 KiB per attempt with the default delegation watermark).

This is trivially reachable from userspace: every failed NFSv4 mount leaks one allocation. A client that persistently retries a mount that cannot succeed leaks kernel memory without bound. Observed in production where a Longhorn backup poller retried mount.nfs4 against an NFSv3-only server roughly 10 times per second, leaking ~3.4 GiB of unreclaimable slab (kmalloc-rnd-13-4k) per day; the node accumulated 12 GiB of leaked slab before the source was identified via the kmem:kmalloc tracepoint (call_site=nfs4_delegation_hash_alloc).

Reproducer:

server exports NFSv3 only (or export path absent for v4)

while :; do mount -t nfs4 :/missing /mnt; done

watch SUnreclaim in /proc/meminfo grow 4 KiB per iteration

Free the table on the error paths between the allocation and the assignment of server->destroy.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89714.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f5b3108e6a14418b120a3c38ca589b8d6cf87627
Fixed
f3adf1643517357221422c05986d6de5df7b9913
Fixed
0fd2b9687dae36be5b84eab39b4c627bb7ab33b3
Fixed
2092f5b38f88be306140c77aeeeb43fc1adacacc

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89714.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.17.0
Fixed
6.18.50
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89714.json"