๐Ÿ” CVE Alert

CVE-2026-89713

CRITICAL 9.1

NFSD: check truncate permission under inode lock

CVSS Score
9.1
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: NFSD: check truncate permission under inode lock nfsd_setattr() checks whether a size update needs NFSD_MAY_TRUNC before it takes inode_lock(). The comparison uses the file size sampled by that unlocked read, but the actual ATTR_SIZE update is applied later under inode_lock() by notify_change(). This leaves a TOCTOU window for append-only files. If a client sends a SETATTR that does not shrink the file at the time of the unlocked sample, a concurrent append can extend the file before nfsd_setattr() takes inode_lock(). notify_change() then applies a real truncation without the NFSD_MAY_TRUNC check that rejects IS_APPEND(inode). The VFS truncate syscall paths perform their own append-only checks before calling notify_change(), so NFSD must make this decision against the locked size it is about to change. Split the write-count acquisition from the truncation permission check. Keep get_write_access() before the locked setattr work, then recheck whether the requested size is below i_size_read(inode) after inode_lock() has been acquired and before notify_change(ATTR_SIZE). This also avoids the plain unlocked inode->i_size load.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 13, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new critical vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
783112f7401ff449d979530209b3f6c2594fdb4e < 3afa17d93ba8c925f49370c816c6dae5112d8c24 783112f7401ff449d979530209b3f6c2594fdb4e < d8352da196349182e1afd5a93308256cddc0a97d 783112f7401ff449d979530209b3f6c2594fdb4e < 44086254479035de42ca3d286ecf25521d4e6325 783112f7401ff449d979530209b3f6c2594fdb4e < b778e0e0a16759f22a70579c3cf8d254a40d4a7f 604a3c407026d6162d15300478e63f901e435efc cc4d5dc73841b98d33cdfb9822d70b0aac4beca5 3ee4f442e5b37a537297b812557b1163f96b5399 a3c6cbc4eac4473ed5461d5faae2794d3e5c0e44 982898d7f97a35447403c3fcecc0d96c646ce101 3.2.89 < 3.3 3.16.44 < 3.17 4.4.53 < 4.5 4.9.14 < 4.10 4.10.2 < 4.11
Linux / Linux
4.11

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/3afa17d93ba8c925f49370c816c6dae5112d8c24 git.kernel.org: https://git.kernel.org/stable/c/d8352da196349182e1afd5a93308256cddc0a97d git.kernel.org: https://git.kernel.org/stable/c/44086254479035de42ca3d286ecf25521d4e6325 git.kernel.org: https://git.kernel.org/stable/c/b778e0e0a16759f22a70579c3cf8d254a40d4a7f