CVE-2026-89698
In the Linux kernel, the following vulnerability has been resolved:
nfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage
struct nfsd_genl_rqstp declares rq_daddr and rq_saddr as plain "struct sockaddr" (16 bytes). When an IPv6 NFS client is connected, nfsd_genl_rpc_status_compose_msg() casts these fields to "struct sockaddr_in6 *" (28 bytes) and reads sin6_addr at offset 8..24, which extends 8 bytes past the end of the 16-byte sockaddr field into the adjacent rq_flags member. The 16-byte nla_put_in6_addr then ships 8 bytes of truncated IPv6 address followed by 8 bytes of rq_flags to userspace via the NFSD_A_RPC_STATUS_SADDR6/DADDR6 netlink attributes.
Leer descripción completaMostrar menos
This is reachable by any unprivileged process in the network namespace because NFSD_CMD_RPC_STATUS_GET uses GENL_CMD_CAP_DUMP without GENL_ADMIN_PERM.
Fix by widening rq_daddr and rq_saddr to struct sockaddr_storage so the IPv6 casts operate within bounds, copying sizeof(struct sockaddr_storage) bytes in the memcpy calls so the full address is captured, and zero-initializing the genl_rqstp stack variable to prevent leaking uninitialized tail bytes through netlink.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-89698",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "bd9d6a3efa9709e653aafbeb859289feccb8e70c",
"lessThan": "9a2e791639a1c5cac3f219b0d2632835d8f88d27",
"versionType": "git"
},
{
"status": "affected",
"version": "bd9d6a3efa9709e653aafbeb859289feccb8e70c",
"lessThan": "03c512f22d3fbe7a3767d6df5e3d88b8e7c105e5",
"versionType": "git"
},
{
"status": "affected",
"version": "bd9d6a3efa9709e653aafbeb859289feccb8e70c",
"lessThan": "dcb69ad0dafb4a24b825183bb94055d5be8a10bd",
"versionType": "git"
},
{
"status": "affected",
"version": "bd9d6a3efa9709e653aafbeb859289feccb8e70c",
"lessThan": "a99d720ed2a5258564e5e9d5f39f3184a030d354",
"versionType": "git"
}
],
"programFiles": [
"fs/nfsd/nfsctl.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.7",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.51",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.4",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"fs/nfsd/nfsctl.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-11T20:19:56.957",
"references": [
{
"url": "https://git.kernel.org/stable/c/03c512f22d3fbe7a3767d6df5e3d88b8e7c105e5",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9a2e791639a1c5cac3f219b0d2632835d8f88d27",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a99d720ed2a5258564e5e9d5f39f3184a030d354",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/dcb69ad0dafb4a24b825183bb94055d5be8a10bd",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage\n\nstruct nfsd_genl_rqstp declares rq_daddr and rq_saddr as plain\n\"struct sockaddr\" (16 bytes). When an IPv6 NFS client is connected,\nnfsd_genl_rpc_status_compose_msg() casts these fields to\n\"struct sockaddr_in6 *\" (28 bytes) and reads sin6_addr at offset 8..24,\nwhich extends 8 bytes past the end of the 16-byte sockaddr field into\nthe adjacent rq_flags member. The 16-byte nla_put_in6_addr then ships 8\nbytes of truncated IPv6 address followed by 8 bytes of rq_flags to\nuserspace via the NFSD_A_RPC_STATUS_SADDR6/DADDR6 netlink attributes.\n\nThis is reachable by any unprivileged process in the network namespace\nbecause NFSD_CMD_RPC_STATUS_GET uses GENL_CMD_CAP_DUMP without\nGENL_ADMIN_PERM.\n\nFix by widening rq_daddr and rq_saddr to struct sockaddr_storage so the\nIPv6 casts operate within bounds, copying sizeof(struct sockaddr_storage)\nbytes in the memcpy calls so the full address is captured, and\nzero-initializing the genl_rqstp stack variable to prevent leaking\nuninitialized tail bytes through netlink."
}
],
"lastModified": "2026-09-21T14:17:25.457",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}