CVE-2026-89710
CVE CVE-2026-89710EUVD EUVD-2026-76622Published 2026-09-11T19:46:25.000ZLast changed 2026-09-14T12:02:09.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: NFSv4.1: fix layout segment leak on the pnfs_layout_process() forget path When the server returns a new layout stateid while a valid one is still held, pnfs_layout_process() calls pnfs_mark_matching_lsegs_return() on the on-stack free_me list and jumps to out_forget. Segments whose reference count drops to zero are unlinked from lo->plh_segs and moved to free_me by mark_lseg_invalid(); for an idle cached segment the layout header holds the only reference, so this happens on the first decrement. out_forget never drains free_me -- only the success path calls pnfs_free_lseg_list(). Commit 814b84971388 ("pNFS/NFSv4: Fix a layout segment leak in pnfs_layout_process()") added the drain; commit 08bd8dbe8882 ("pNFS/NFSv4: Try to return invalid layout in pnfs_layout_process()") removed it while switching the destination to lo->plh_return_segs, which is drained elsewhere. Commit fb700ef02676 ("NFSv4.1: Simplify layout return in pnfs_layout_process()") switched the destination back to free_me without restoring the drain. Restore the pnfs_free_lseg_list() call.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 0; patch: 5.15.221; fb700ef026766c95578aafc0db1b208946e7ad4f <ee5a386cfe60f3f8286de16a9db8e1a08f0bc124; patch: 7.2.4; fb700ef026766c95578aafc0db1b208946e7ad4f <ad3e41855325e55623276660ef20fbc3b8ba087f; patch: 6.12.109; patch: 6.6.157; patch: 6.1.188; fb700ef026766c95578aafc0db1b208946e7ad4f <32ac1b0b7f1cfa0d1a1faf9c72f4154046101070; fb700ef026766c95578aafc0db1b208946e7ad4f <7c5b0e813efd9124760d5fd1bfc6b229f03fb1a2; fb700ef026766c95578aafc0db1b208946e7ad4f <36e3f13bf0728f4ce11ee8904cec82a783222f62; patch: 6.18.50; patch: 7.3-rc1; 5.13; fb700ef026766c95578aafc0db1b208946e7ad4f <a080bb69d30f11738d753a60d1eb733d627c2093; fb700ef026766c95578aafc0db1b208946e7ad4f <f52188118d319b47d49ee91a897f6afda4879c59
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.