๐Ÿ” CVE Alert

CVE-2026-89702

CRITICAL 9.8

nfsd: size fh_verify server sockaddr slot by xpt_locallen

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: nfsd: size fh_verify server sockaddr slot by xpt_locallen The nfsd_fh_verify and nfsd_fh_verify_err tracepoints declare the server sockaddr slot sized by xpt_remotelen but fill it from xpt_local using xpt_locallen: TP_STRUCT__entry( ... __sockaddr(server, rqstp->rq_xprt->xpt_remotelen) ... ) TP_fast_assign( ... __assign_sockaddr(server, &rqstp->rq_xprt->xpt_local, rqstp->rq_xprt->xpt_locallen); ... ) When xpt_locallen exceeds xpt_remotelen, __assign_sockaddr's memcpy writes past the reserved ring-buffer slot. In the reverse direction (xpt_locallen < xpt_remotelen) the slot is oversized and the unwritten tail leaks prior ring-buffer contents to trace consumers. The write-past-end case is reachable on NFS/UDP. svc_xprt_set_remote() is only called from svc_tcp_accept() (net/sunrpc/svcsock.c) and from the RDMA connect path; svc_create_socket() for UDP calls only svc_xprt_set_local(), so xpt_remotelen stays 0 for the xprt's lifetime. Every fh_verify trace for an NFSv2/v3-over-UDP request then copies 16 or 28 bytes from xpt_local into a zero-byte slot. The other NFSD tracepoints that record the server address (NFSD_TRACE_PROC_CALL_FIELDS, NFSD_TRACE_PROC_RES_FIELDS, SVC_RQST_ENDPOINT_FIELDS) already size the server slot by xpt_locallen; nfsd_fh_verify and nfsd_fh_verify_err were the only exceptions. Fix by sizing the server slot with xpt_locallen so the declared slot matches the copy length. The client slot and its assignment already agree on xpt_remotelen and are left untouched.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 13, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new critical vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
051382885552e12541cc0ebf82092be374a9ed2a < 95d064f9828a20ccca5ae90a17be3e2076f25272 051382885552e12541cc0ebf82092be374a9ed2a < 7ff8d6363cffff45654ea85e319f7c0c54226012 051382885552e12541cc0ebf82092be374a9ed2a < 719a10e3f5f868c3c4ac3cf3648c5775d12034bd 051382885552e12541cc0ebf82092be374a9ed2a < 71d068490098b1d23c63b2345e40675d3a1ca763 dcbebc86850324fbe0a993ce352f0539cd98038a 62980365d6e894234b29f44fb2bfad4f7f8bb824 5.15.154 < 5.16
Linux / Linux
6.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/95d064f9828a20ccca5ae90a17be3e2076f25272 git.kernel.org: https://git.kernel.org/stable/c/7ff8d6363cffff45654ea85e319f7c0c54226012 git.kernel.org: https://git.kernel.org/stable/c/719a10e3f5f868c3c4ac3cf3648c5775d12034bd git.kernel.org: https://git.kernel.org/stable/c/71d068490098b1d23c63b2345e40675d3a1ca763