CVE-2026-89674
Published: September 15, 2026Last modified: September 15, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget The XDR buffer size calculation in nfsd4_ff_encode_layoutget() has multiple errors that can result in either an out-of-bounds write or leaking uninitialized kernel memory to the client: - fh_len doesn't account for XDR padding on the file handle data - uid and gid lengths use "8 + len" but xdr_encode_opaque() actually writes "4 + xdr_align_size(len)" bytes - ds_len omits the flags and stats_collect_hint fields (8 bytes), while len's header constant overestimates by 8 bytes -- these partially cancel but leave a net mismatch The worst case occurs with short strings (e.g. uid=0, gid=0 with an odd-sized file handle), where the function writes up to 5 bytes past the reserved XDR buffer. Conversely, when string lengths happen to be 4-byte aligned, the reservation is too large and stale buffer content is sent to the client. Fix this by breaking out every encoded field explicitly in the ds_len calculation, using xdr_align_size() for all variable-length opaque fields, and correcting the header constants.
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score | 9.8 |
| Attack Vector | NETWORK |
| Attack complexity | LOW |
| Privileges required | NONE |
| User interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality | HIGH |
| Integrity impact | HIGH |
| Availability impact | HIGH |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Status
| Product | Release | Package | Status |
|---|---|---|---|
| Alpaquita Linux | 23 LTS | linux-lts | Vulnerable (6.1.182-r0) |
| 25 LTS | linux-lts | Vulnerable (6.12.103-r0) | |
| Stream | linux-lts | Vulnerable (6.18.46-r0) |
References
- https://git.kernel.org/stable/c/0380129b1373c437eb35401a174671c8888f4b80
- https://git.kernel.org/stable/c/29e4478e2ed5a227e8f0c33cacb91bf227cedd47
- https://git.kernel.org/stable/c/3a7fd224df0fbb42167eb1b77be45d72fe0b1098
- https://git.kernel.org/stable/c/65a72b721943618eeb3a41c8b36e915591f3f83f
- https://git.kernel.org/stable/c/bee826c00ac900473f91306f1f3e5a5a81fd4a74
- https://git.kernel.org/stable/c/c81cef6a805dec266c10fc4f83c93d6fcf1a2b43
- https://git.kernel.org/stable/c/e7d9d23ecd9172f05b09bb678ff22db8e361c428
- https://git.kernel.org/stable/c/f9868174af49d207fbaf0c5e055d088a983684af