CVE-2026-89674
In the Linux kernel, the following vulnerability has been resolved:
nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget
The XDR buffer size calculation in nfsd4_ff_encode_layoutget() has multiple errors that can result in either an out-of-bounds write or leaking uninitialized kernel memory to the client:
The worst case occurs with short strings (e.g. uid=0, gid=0 with an odd-sized file handle), where the function writes up to 5 bytes past the reserved XDR buffer. Conversely, when string lengths happen to be 4-byte aligned, the reservation is too large and stale buffer content is sent to the client.
Leer descripción completaMostrar menos
Fix this by breaking out every encoded field explicitly in the ds_len calculation, using xdr_align_size() for all variable-length opaque fields, and correcting the header constants.
Detalles técnicos trazas, registros y código del informe original
- fh_len doesn't account for XDR padding on the file handle data - uid and gid lengths use "8 + len" but xdr_encode_opaque() actually writes "4 + xdr_align_size(len)" bytes - ds_len omits the flags and stats_collect_hint fields (8 bytes), while len's header constant overestimates by 8 bytes -- these partially cancel but leave a net mismatch
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.51%
- Percentil entre todas las CVEs puntuadas: 42
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access85 % - Impacto principal
T1565.001Stored Data Manipulationimpact75 % - Impacto secundario
T1552.001Credentials In Filescredential access80 %
Vulnerabilidad remota de kernel Linux (AV:N, PR:N, UI:N) en servicio NFS que permite corrupción de memoria XDR (escritura fuera de límites) e información sensible sin inicializar.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/0380129b1373c437eb35401a174671c8888f4b80
- https://git.kernel.org/stable/c/29e4478e2ed5a227e8f0c33cacb91bf227cedd47
- https://git.kernel.org/stable/c/3a7fd224df0fbb42167eb1b77be45d72fe0b1098
- https://git.kernel.org/stable/c/65a72b721943618eeb3a41c8b36e915591f3f83f
- https://git.kernel.org/stable/c/bee826c00ac900473f91306f1f3e5a5a81fd4a74
- https://git.kernel.org/stable/c/c81cef6a805dec266c10fc4f83c93d6fcf1a2b43
- https://git.kernel.org/stable/c/e7d9d23ecd9172f05b09bb678ff22db8e361c428
- https://git.kernel.org/stable/c/f9868174af49d207fbaf0c5e055d088a983684af
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-89674",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "9b9960a0ca4773e21c4b153ed355583946346b25",
"lessThan": "3a7fd224df0fbb42167eb1b77be45d72fe0b1098",
"versionType": "git"
},
{
"status": "affected",
"version": "9b9960a0ca4773e21c4b153ed355583946346b25",
"lessThan": "29e4478e2ed5a227e8f0c33cacb91bf227cedd47",
"versionType": "git"
},
{
"status": "affected",
"version": "9b9960a0ca4773e21c4b153ed355583946346b25",
"lessThan": "65a72b721943618eeb3a41c8b36e915591f3f83f",
"versionType": "git"
},
{
"status": "affected",
"version": "9b9960a0ca4773e21c4b153ed355583946346b25",
"lessThan": "bee826c00ac900473f91306f1f3e5a5a81fd4a74",
"versionType": "git"
},
{
"status": "affected",
"version": "9b9960a0ca4773e21c4b153ed355583946346b25",
"lessThan": "e7d9d23ecd9172f05b09bb678ff22db8e361c428",
"versionType": "git"
},
{
"status": "affected",
"version": "9b9960a0ca4773e21c4b153ed355583946346b25",
"lessThan": "0380129b1373c437eb35401a174671c8888f4b80",
"versionType": "git"
},
{
"status": "affected",
"version": "9b9960a0ca4773e21c4b153ed355583946346b25",
"lessThan": "c81cef6a805dec266c10fc4f83c93d6fcf1a2b43",
"versionType": "git"
},
{
"status": "affected",
"version": "9b9960a0ca4773e21c4b153ed355583946346b25",
"lessThan": "f9868174af49d207fbaf0c5e055d088a983684af",
"versionType": "git"
}
],
"programFiles": [
"fs/nfsd/flexfilelayoutxdr.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.8"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.8",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.270",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.221",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.188",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.157",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.109",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.50",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.4",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"fs/nfsd/flexfilelayoutxdr.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-11T20:19:54.013",
"references": [
{
"url": "https://git.kernel.org/stable/c/0380129b1373c437eb35401a174671c8888f4b80",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/29e4478e2ed5a227e8f0c33cacb91bf227cedd47",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/3a7fd224df0fbb42167eb1b77be45d72fe0b1098",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/65a72b721943618eeb3a41c8b36e915591f3f83f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/bee826c00ac900473f91306f1f3e5a5a81fd4a74",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c81cef6a805dec266c10fc4f83c93d6fcf1a2b43",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e7d9d23ecd9172f05b09bb678ff22db8e361c428",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f9868174af49d207fbaf0c5e055d088a983684af",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget\n\nThe XDR buffer size calculation in nfsd4_ff_encode_layoutget() has\nmultiple errors that can result in either an out-of-bounds write or\nleaking uninitialized kernel memory to the client:\n\n - fh_len doesn't account for XDR padding on the file handle data\n - uid and gid lengths use \"8 + len\" but xdr_encode_opaque() actually\n writes \"4 + xdr_align_size(len)\" bytes\n - ds_len omits the flags and stats_collect_hint fields (8 bytes),\n while len's header constant overestimates by 8 bytes -- these\n partially cancel but leave a net mismatch\n\nThe worst case occurs with short strings (e.g. uid=0, gid=0 with an\nodd-sized file handle), where the function writes up to 5 bytes past\nthe reserved XDR buffer. Conversely, when string lengths happen to be\n4-byte aligned, the reservation is too large and stale buffer content\nis sent to the client.\n\nFix this by breaking out every encoded field explicitly in the ds_len\ncalculation, using xdr_align_size() for all variable-length opaque\nfields, and correcting the header constants."
}
],
"lastModified": "2026-09-14T13:19:19.450",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}