๐Ÿ” CVE Alert

CVE-2026-89674

CRITICAL 9.8

nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget The XDR buffer size calculation in nfsd4_ff_encode_layoutget() has multiple errors that can result in either an out-of-bounds write or leaking uninitialized kernel memory to the client: - fh_len doesn't account for XDR padding on the file handle data - uid and gid lengths use "8 + len" but xdr_encode_opaque() actually writes "4 + xdr_align_size(len)" bytes - ds_len omits the flags and stats_collect_hint fields (8 bytes), while len's header constant overestimates by 8 bytes -- these partially cancel but leave a net mismatch The worst case occurs with short strings (e.g. uid=0, gid=0 with an odd-sized file handle), where the function writes up to 5 bytes past the reserved XDR buffer. Conversely, when string lengths happen to be 4-byte aligned, the reservation is too large and stale buffer content is sent to the client. Fix this by breaking out every encoded field explicitly in the ds_len calculation, using xdr_align_size() for all variable-length opaque fields, and correcting the header constants.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new critical vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
9b9960a0ca4773e21c4b153ed355583946346b25 < 3a7fd224df0fbb42167eb1b77be45d72fe0b1098 9b9960a0ca4773e21c4b153ed355583946346b25 < 29e4478e2ed5a227e8f0c33cacb91bf227cedd47 9b9960a0ca4773e21c4b153ed355583946346b25 < 65a72b721943618eeb3a41c8b36e915591f3f83f 9b9960a0ca4773e21c4b153ed355583946346b25 < bee826c00ac900473f91306f1f3e5a5a81fd4a74 9b9960a0ca4773e21c4b153ed355583946346b25 < e7d9d23ecd9172f05b09bb678ff22db8e361c428 9b9960a0ca4773e21c4b153ed355583946346b25 < 0380129b1373c437eb35401a174671c8888f4b80 9b9960a0ca4773e21c4b153ed355583946346b25 < c81cef6a805dec266c10fc4f83c93d6fcf1a2b43 9b9960a0ca4773e21c4b153ed355583946346b25 < f9868174af49d207fbaf0c5e055d088a983684af
Linux / Linux
4.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/3a7fd224df0fbb42167eb1b77be45d72fe0b1098 git.kernel.org: https://git.kernel.org/stable/c/29e4478e2ed5a227e8f0c33cacb91bf227cedd47 git.kernel.org: https://git.kernel.org/stable/c/65a72b721943618eeb3a41c8b36e915591f3f83f git.kernel.org: https://git.kernel.org/stable/c/bee826c00ac900473f91306f1f3e5a5a81fd4a74 git.kernel.org: https://git.kernel.org/stable/c/e7d9d23ecd9172f05b09bb678ff22db8e361c428 git.kernel.org: https://git.kernel.org/stable/c/0380129b1373c437eb35401a174671c8888f4b80 git.kernel.org: https://git.kernel.org/stable/c/c81cef6a805dec266c10fc4f83c93d6fcf1a2b43 git.kernel.org: https://git.kernel.org/stable/c/f9868174af49d207fbaf0c5e055d088a983684af