{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.2.6-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  NFS/localio: fix ref leak on nfs_uuid_add_file failure  When nfs_uuid_add_file() races with nfs_uuid_put() tearing down uuid-\u003enet, it returns -ENXIO without publishing nfl-\u003enfs_uuid via rcu_assign_pointer().  nfs_open_local_fh() then enters its error branch and only releases the slot's file ref and its paired net ref plus its own entry-time net ref, while the close path is a no-op:      nfs_close_local_fh()       nfs_uuid = rcu_dereference(nfl-\u003enfs_uuid);       if (!nfs_uuid) { rcu_read_unlock(); return; }  /* always */  nfsd_open_local_fh() returns localio holding a caller-owned +1 nfsd_file reference (from nfsd_file_get() after nfsd_file_acquire_local()) and an entry-time nfsd_net reference (from its first nfsd_net_try_get()) embedded as nf-\u003enf_net.  Both are leaked on the failure path, pinning one nfsd_file (and the underlying struct file, dentry, inode) and one nfsd_net_ref per occurrence, which blocks nfsd_net and netns teardown.  Fix by releasing the caller-owned file ref and its net ref through the existing helper, using a stack-local RCU pointer so the helper can xchg it out, then returning -ENXIO so callers do not dereference a localio whose slot has been cleared:      struct nfsd_file __rcu *tmp = RCU_INITIALIZER(localio);      nfs_to_nfsd_file_put_local(pnf);     nfs_to_nfsd_file_put_local(\u0026tmp);     localio = ERR_PTR(-ENXIO);  The trailing nfs_to_nfsd_net_put(net) continues to release the outer net ref, so all three nfsd_net_try_get() increments are balanced on the error branch.",
  "id": "DEBIAN-CVE-2026-89715",
  "modified": "2026-09-23T03:47:31.931269858Z",
  "published": "2026-09-11T20:19:58.993Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-89715"
    }
  ],
  "upstream": [
    "CVE-2026-89715"
  ]
}