CVE-2026-89691
Received Received - Intake

Out-of-Bounds Read in Linux Kernel NFS Server

Vulnerability report for CVE-2026-89691, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-13

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: nfsd: clear opcnt on compound arg release to prevent OOB read nfsd4_release_compoundargs() resets args->ops to the inline iops[8] array when the dynamically-allocated ops buffer is freed, but leaves args->opcnt at its original value (which can be up to 200 for NFSv4.1+ compounds). If rq_status_counter is stuck at an odd value (which can happen when nfsd_dispatch() hits an error path after setting it odd), the RPC status dumpit handler reads min(opcnt, 16) entries from args->ops[]. Since iops only has 8 elements and is the last field in struct nfsd4_compoundargs, reading indices 8-15 accesses adjacent slab memory and leaks it to userspace via netlink. Zero opcnt unconditionally in nfsd4_release_compoundargs() so stale compound metadata is never exposed through the status interface. [ cel: Remove the kvfree_rcu_mightsleep() sleep from the exposure window ]

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-13
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves an out-of-bounds (OOB) read issue in the NFS server (nfsd) component. When processing compound arguments in NFSv4.1+, the function nfsd4_release_compoundargs() fails to reset the opcnt field to zero after freeing the dynamically-allocated ops buffer. This leaves opcnt at a value up to 200, while the inline iops array only has 8 elements. If certain error conditions occur, the RPC status handler reads up to 16 entries from the ops array, causing it to access adjacent slab memory and leak sensitive data to userspace via netlink.

Detection Guidance

This vulnerability is specific to the Linux kernel's NFS server implementation. Detection requires checking kernel logs for NFS-related errors or examining kernel memory for slab corruption. No direct commands are provided in the context, but monitoring for NFS server crashes or unusual slab memory access patterns may indicate exploitation.

Impact Analysis

This vulnerability could allow an attacker to read sensitive kernel memory from userspace. If exploited, it may lead to information disclosure, including potentially confidential data processed by the NFS server. Attackers could leverage this to gain insights into system memory layout or extract sensitive information, though exploitation requires specific error conditions to be met.

Compliance Impact

This vulnerability involves an out-of-bounds (OOB) read in the Linux kernel's NFS server, potentially exposing adjacent slab memory to userspace. While not directly tied to GDPR or HIPAA, such memory leaks could compromise data confidentiality, a key requirement under these regulations. Unauthorized memory exposure may lead to data breaches, violating principles like data minimization (GDPR) or integrity and confidentiality safeguards (HIPAA).

Mitigation Strategies

Apply the latest kernel patches from your Linux distribution to resolve the issue. If patching is not immediately possible, disable the NFS server service (nfsd) to prevent exploitation until the patch is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89691. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart