« Volver al listado

CVE-2026-89698

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

nfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage

struct nfsd_genl_rqstp declares rq_daddr and rq_saddr as plain "struct sockaddr" (16 bytes). When an IPv6 NFS client is connected, nfsd_genl_rpc_status_compose_msg() casts these fields to "struct sockaddr_in6 *" (28 bytes) and reads sin6_addr at offset 8..24, which extends 8 bytes past the end of the 16-byte sockaddr field into the adjacent rq_flags member. The 16-byte nla_put_in6_addr then ships 8 bytes of truncated IPv6 address followed by 8 bytes of rq_flags to userspace via the NFSD_A_RPC_STATUS_SADDR6/DADDR6 netlink attributes.

Leer descripción completaMostrar menos

This is reachable by any unprivileged process in the network namespace because NFSD_CMD_RPC_STATUS_GET uses GENL_CMD_CAP_DUMP without GENL_ADMIN_PERM.

Fix by widening rq_daddr and rq_saddr to struct sockaddr_storage so the IPv6 casts operate within bounds, copying sizeof(struct sockaddr_storage) bytes in the memcpy calls so the full address is captured, and zero-initializing the genl_rqstp stack variable to prevent leaking uninitialized tail bytes through netlink.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89698",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "bd9d6a3efa9709e653aafbeb859289feccb8e70c",
              "lessThan": "9a2e791639a1c5cac3f219b0d2632835d8f88d27",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bd9d6a3efa9709e653aafbeb859289feccb8e70c",
              "lessThan": "03c512f22d3fbe7a3767d6df5e3d88b8e7c105e5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bd9d6a3efa9709e653aafbeb859289feccb8e70c",
              "lessThan": "dcb69ad0dafb4a24b825183bb94055d5be8a10bd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bd9d6a3efa9709e653aafbeb859289feccb8e70c",
              "lessThan": "a99d720ed2a5258564e5e9d5f39f3184a030d354",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/nfsd/nfsctl.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.7"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.7",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.51",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/nfsd/nfsctl.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-11T20:19:56.957",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/03c512f22d3fbe7a3767d6df5e3d88b8e7c105e5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9a2e791639a1c5cac3f219b0d2632835d8f88d27",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a99d720ed2a5258564e5e9d5f39f3184a030d354",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/dcb69ad0dafb4a24b825183bb94055d5be8a10bd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage\n\nstruct nfsd_genl_rqstp declares rq_daddr and rq_saddr as plain\n\"struct sockaddr\" (16 bytes). When an IPv6 NFS client is connected,\nnfsd_genl_rpc_status_compose_msg() casts these fields to\n\"struct sockaddr_in6 *\" (28 bytes) and reads sin6_addr at offset 8..24,\nwhich extends 8 bytes past the end of the 16-byte sockaddr field into\nthe adjacent rq_flags member. The 16-byte nla_put_in6_addr then ships 8\nbytes of truncated IPv6 address followed by 8 bytes of rq_flags to\nuserspace via the NFSD_A_RPC_STATUS_SADDR6/DADDR6 netlink attributes.\n\nThis is reachable by any unprivileged process in the network namespace\nbecause NFSD_CMD_RPC_STATUS_GET uses GENL_CMD_CAP_DUMP without\nGENL_ADMIN_PERM.\n\nFix by widening rq_daddr and rq_saddr to struct sockaddr_storage so the\nIPv6 casts operate within bounds, copying sizeof(struct sockaddr_storage)\nbytes in the memcpy calls so the full address is captured, and\nzero-initializing the genl_rqstp stack variable to prevent leaking\nuninitialized tail bytes through netlink."
    }
  ],
  "lastModified": "2026-09-21T14:17:25.457",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}