PT-2026-90407 · Linux · Linux

CVE-2026-89691

·

Publicado

2026-09-11

·

Atualizado

2026-09-11

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
nfsd: clear opcnt on compound arg release to prevent OOB read
nfsd4 release compoundargs() resets args->ops to the inline iops[8] array when the dynamically-allocated ops buffer is freed, but leaves args->opcnt at its original value (which can be up to 200 for NFSv4.1+ compounds).
If rq status counter is stuck at an odd value (which can happen when nfsd dispatch() hits an error path after setting it odd), the RPC status dumpit handler reads min(opcnt, 16) entries from args->ops[]. Since iops only has 8 elements and is the last field in struct nfsd4 compoundargs, reading indices 8-15 accesses adjacent slab memory and leaks it to userspace via netlink.
Zero opcnt unconditionally in nfsd4 release compoundargs() so stale compound metadata is never exposed through the status interface.
[ cel: Remove the kvfree rcu mightsleep() sleep from the exposure window ]
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-89691

Produtos afetados

Linux