PT-2026-90407 · Linux · Linux

CVE-2026-89691

·

Published

2026-09-11

·

Updated

2026-09-11

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
nfsd: clear opcnt on compound arg release to prevent OOB read
nfsd4 release compoundargs() resets args->ops to the inline iops[8] array when the dynamically-allocated ops buffer is freed, but leaves args->opcnt at its original value (which can be up to 200 for NFSv4.1+ compounds).
If rq status counter is stuck at an odd value (which can happen when nfsd dispatch() hits an error path after setting it odd), the RPC status dumpit handler reads min(opcnt, 16) entries from args->ops[]. Since iops only has 8 elements and is the last field in struct nfsd4 compoundargs, reading indices 8-15 accesses adjacent slab memory and leaks it to userspace via netlink.
Zero opcnt unconditionally in nfsd4 release compoundargs() so stale compound metadata is never exposed through the status interface.
[ cel: Remove the kvfree rcu mightsleep() sleep from the exposure window ]
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-89691

Affected Products

Linux