๐Ÿ” CVE Alert

CVE-2026-89701

UNKNOWN 0.0

nfsd: validate nseconds in TIME_DELEG decode paths

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: nfsd: validate nseconds in TIME_DELEG decode paths The xdrgen-based TIME_DELEG_ACCESS and TIME_DELEG_MODIFY decode arms store a raw uint32_t nseconds directly into tv_nsec without enforcing nseconds < NSEC_PER_SEC. The legacy nfsd4_decode_nfstime4 has this check but the TIME_DELEG paths do not. A malformed timespec can propagate through notify_change() to disk. Add range checks in both nfs4xdr.c (SETATTR path) and nfs4callback.c (CB_GETATTR path).

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
6ae30d6eb26bce02c48c60074b4306270e2434c1 < 7e7b93da7fa2e77f977096251899d1410986adf6 6ae30d6eb26bce02c48c60074b4306270e2434c1 < 5eb489831a9fd4754f4baf26e6989efb66ce104c 6ae30d6eb26bce02c48c60074b4306270e2434c1 < 0f4a767340fad392bd656115b8752005518c9065
Linux / Linux
6.14

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/7e7b93da7fa2e77f977096251899d1410986adf6 git.kernel.org: https://git.kernel.org/stable/c/5eb489831a9fd4754f4baf26e6989efb66ce104c git.kernel.org: https://git.kernel.org/stable/c/0f4a767340fad392bd656115b8752005518c9065