CVE-2026-89678
In the Linux kernel, the following vulnerability has been resolved:
nfsd: fix partial-write detection in nfsd_direct_write
nfsd_direct_write() walks a list of write segments and, after each vfs_iocb_iter_write(), tries to detect a short write so the loop can stop before placing the next segment at a wrong file offset:
vfs_iocb_iter_write() runs the iter through ->write_iter(), which advances the iter by the number of bytes written. By the time the check runs, segments[i].iter.count is the residual, not the original request length:
The condition then reduces to host_err < original_len - host_err, so the break fires only when less than half of the segment was written.
Leer descripción completaMostrar menos
Any short write completing between 50% and 99% of the segment slips through; the loop advances to the next segment with kiocb->ki_pos only bumped by the short amount, writing the next segment's payload at the wrong offset and over-reporting *cnt to the NFS client.
Snapshot the segment's byte count before the write and compare host_err against that snapshot so any short write breaks the loop.
Detalles técnicos trazas, registros y código del informe original
host_err = vfs_iocb_iter_write(file, kiocb, &segments[i].iter);
if (host_err < 0)
return host_err;
*cnt += host_err;
if (host_err < segments[i].iter.count)
break; /* partial write */
before write_iter: iter.count == original_len
after write_iter: iter.count == original_len - host_errCVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.38%
- Percentil entre todas las CVEs puntuadas: 30
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access75 % - Impacto principal
T1565.002Transmitted Data Manipulationimpact85 % - Impacto secundario
T1499.004Application or System Exploitationimpact60 %
Vulnerabilidad remota sin autenticación en kernel Linux (AV:N/PR:N) que permite corrupción de datos en escrituras NFS parciales y denegación de servicio al sobrescribir archivos con contenido desalineado.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-89678",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "06c5c97293e3fca99ce15da157068edf45a7c6e4",
"lessThan": "fa6590dfd16ab55f03b658b079072ace3504825e",
"versionType": "git"
},
{
"status": "affected",
"version": "06c5c97293e3fca99ce15da157068edf45a7c6e4",
"lessThan": "250ec14932d5cfe102f68a57892bb566eee7f83e",
"versionType": "git"
}
],
"programFiles": [
"fs/nfsd/vfs.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.19"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.19",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.2.4",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"fs/nfsd/vfs.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-11T20:19:54.523",
"references": [
{
"url": "https://git.kernel.org/stable/c/250ec14932d5cfe102f68a57892bb566eee7f83e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/fa6590dfd16ab55f03b658b079072ace3504825e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: fix partial-write detection in nfsd_direct_write\n\nnfsd_direct_write() walks a list of write segments and, after each\nvfs_iocb_iter_write(), tries to detect a short write so the loop can\nstop before placing the next segment at a wrong file offset:\n\n host_err = vfs_iocb_iter_write(file, kiocb, &segments[i].iter);\n if (host_err < 0)\n return host_err;\n *cnt += host_err;\n if (host_err < segments[i].iter.count)\n break;\t/* partial write */\n\nvfs_iocb_iter_write() runs the iter through ->write_iter(), which\nadvances the iter by the number of bytes written. By the time the\ncheck runs, segments[i].iter.count is the residual, not the original\nrequest length:\n\n before write_iter: iter.count == original_len\n after write_iter: iter.count == original_len - host_err\n\nThe condition then reduces to host_err < original_len - host_err, so\nthe break fires only when less than half of the segment was written.\nAny short write completing between 50% and 99% of the segment slips\nthrough; the loop advances to the next segment with kiocb->ki_pos\nonly bumped by the short amount, writing the next segment's payload\nat the wrong offset and over-reporting *cnt to the NFS client.\n\nSnapshot the segment's byte count before the write and compare\nhost_err against that snapshot so any short write breaks the loop."
}
],
"lastModified": "2026-09-13T07:17:33.533",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}