# CVE-2026-89707

## Summary

- **CVE ID:** CVE-2026-89707
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 14, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

nfsd: release path refs on follow_down() error

nfsd_cross_mnt() initializes a local struct path with mntget() and
dget() before calling follow_down(). On a negative return the error
arm jumps to out without releasing those references:

    err = follow_down(&path, follow_flags);
    if (err < 0)
            goto out;

follow_down() never drops the caller's entry-time refs on any error
sub-case; for example a pre-cross d_manage() failure leaves path
untouched, so the mntget()/dget() taken on entry survive the call.

Every other early-exit arm in nfsd_cross_mnt() (other-namespace
return, IS_ERR(exp2), and the success tail after the swap) already
calls path_put(&path); the err < 0 arm is the lone omission. The
leak inflates mnt_count and d_count on each failed cross-mount,
blocking umount and pinning dentries against the shrinker, and is
reachable by any authenticated NFS client through nfsd_lookup_dentry
or the NFSv4 READDIR encode path.

Fix by calling path_put(&path) before the goto out in the err < 0
arm so the entry-time refs are released on all follow_down() error
returns.

## Affected Products

- Linux — Linux (cc53ce53c86924bfe98a12ea20b7465038a08792)
- Linux — Linux (2.6.38)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)
- Linux — Linux (6.6.157)

## References

- [CNA](https://git.kernel.org/stable/c/194316df81263519156ebe714c4a286bee00e5be)
- [CNA](https://git.kernel.org/stable/c/467d56fd3ff57447a790c6dc3ede2d02a947d224)
- [CNA](https://git.kernel.org/stable/c/2bc4343308d85ee4e0dd3877b384306c96f114c2)
- [CNA](https://git.kernel.org/stable/c/6cba08dc1922140d260cfeb30bbda4ee1bf869d8)
- [CNA](https://git.kernel.org/stable/c/085cfde7c2186acaad103f02d2c25435ad5224e9)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.60%
- **EPSS Percentile:** 47.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._