« Volver al listado

CVE-2026-89674

Estado: RecibidaCrítica (9.8)—

In the Linux kernel, the following vulnerability has been resolved:

nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget

The XDR buffer size calculation in nfsd4_ff_encode_layoutget() has multiple errors that can result in either an out-of-bounds write or leaking uninitialized kernel memory to the client:

The worst case occurs with short strings (e.g. uid=0, gid=0 with an odd-sized file handle), where the function writes up to 5 bytes past the reserved XDR buffer. Conversely, when string lengths happen to be 4-byte aligned, the reservation is too large and stale buffer content is sent to the client.

Leer descripción completaMostrar menos

Fix this by breaking out every encoded field explicitly in the ds_len calculation, using xdr_align_size() for all variable-length opaque fields, and correcting the header constants.

Detalles técnicos trazas, registros y código del informe original
 - fh_len doesn't account for XDR padding on the file handle data
 - uid and gid lengths use "8 + len" but xdr_encode_opaque() actually
   writes "4 + xdr_align_size(len)" bytes
 - ds_len omits the flags and stats_collect_hint fields (8 bytes),
   while len's header constant overestimates by 8 bytes -- these
   partially cancel but leave a net mismatch

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad remota de kernel Linux (AV:N, PR:N, UI:N) en servicio NFS que permite corrupción de memoria XDR (escritura fuera de límites) e información sensible sin inicializar.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89674",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "9b9960a0ca4773e21c4b153ed355583946346b25",
              "lessThan": "3a7fd224df0fbb42167eb1b77be45d72fe0b1098",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9b9960a0ca4773e21c4b153ed355583946346b25",
              "lessThan": "29e4478e2ed5a227e8f0c33cacb91bf227cedd47",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9b9960a0ca4773e21c4b153ed355583946346b25",
              "lessThan": "65a72b721943618eeb3a41c8b36e915591f3f83f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9b9960a0ca4773e21c4b153ed355583946346b25",
              "lessThan": "bee826c00ac900473f91306f1f3e5a5a81fd4a74",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9b9960a0ca4773e21c4b153ed355583946346b25",
              "lessThan": "e7d9d23ecd9172f05b09bb678ff22db8e361c428",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9b9960a0ca4773e21c4b153ed355583946346b25",
              "lessThan": "0380129b1373c437eb35401a174671c8888f4b80",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9b9960a0ca4773e21c4b153ed355583946346b25",
              "lessThan": "c81cef6a805dec266c10fc4f83c93d6fcf1a2b43",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9b9960a0ca4773e21c4b153ed355583946346b25",
              "lessThan": "f9868174af49d207fbaf0c5e055d088a983684af",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/nfsd/flexfilelayoutxdr.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.8"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.8",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.270",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.221",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.109",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.50",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/nfsd/flexfilelayoutxdr.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-11T20:19:54.013",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0380129b1373c437eb35401a174671c8888f4b80",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/29e4478e2ed5a227e8f0c33cacb91bf227cedd47",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3a7fd224df0fbb42167eb1b77be45d72fe0b1098",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/65a72b721943618eeb3a41c8b36e915591f3f83f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bee826c00ac900473f91306f1f3e5a5a81fd4a74",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c81cef6a805dec266c10fc4f83c93d6fcf1a2b43",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e7d9d23ecd9172f05b09bb678ff22db8e361c428",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f9868174af49d207fbaf0c5e055d088a983684af",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget\n\nThe XDR buffer size calculation in nfsd4_ff_encode_layoutget() has\nmultiple errors that can result in either an out-of-bounds write or\nleaking uninitialized kernel memory to the client:\n\n - fh_len doesn't account for XDR padding on the file handle data\n - uid and gid lengths use \"8 + len\" but xdr_encode_opaque() actually\n   writes \"4 + xdr_align_size(len)\" bytes\n - ds_len omits the flags and stats_collect_hint fields (8 bytes),\n   while len's header constant overestimates by 8 bytes -- these\n   partially cancel but leave a net mismatch\n\nThe worst case occurs with short strings (e.g. uid=0, gid=0 with an\nodd-sized file handle), where the function writes up to 5 bytes past\nthe reserved XDR buffer. Conversely, when string lengths happen to be\n4-byte aligned, the reservation is too large and stale buffer content\nis sent to the client.\n\nFix this by breaking out every encoded field explicitly in the ds_len\ncalculation, using xdr_align_size() for all variable-length opaque\nfields, and correcting the header constants."
    }
  ],
  "lastModified": "2026-09-14T13:19:19.450",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}