PT-2026-90411 · Linux · Linux
CVE-2026-89695
·
Published
2026-09-11
·
Updated
2026-09-11
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
nfsd: cap decoded POSIX ACL count to bound sort cost
nfsd4 decode posixacl() reads a u32 entry count off the wire and passes
it straight to posix acl alloc() and sort pacl range(). The latter is
an O(n^2) bubble sort, so a client-chosen count drives unbounded CPU in
the server's compound processing path.
nfsd4 decode posixacl()
xdr stream decode u32(&count) /* uncapped u32 */
posix acl alloc(count, GFP KERNEL)
sort pacl range(acl, 0, count - 1) / O(n^2) bubble sort */
The encoder side in the same file already rejects ACLs whose a count
exceeds NFS ACL MAX ENTRIES, but the decoder introduced in commit
5fc51dfc2eb1 ("NFSD: Add support for XDR decoding POSIX draft ACLs")
omitted the symmetric check.
Fix by rejecting a wire count greater than NFS ACL MAX ENTRIES with
nfserr inval, before any allocation, so the sort is bounded by
NFS ACL MAX ENTRIES^2 comparisons.
While we're in here, also fix the nfserr resource return if
posix acl alloc() fails. That's not a legal error code for v4.1+. Change
it to return nfserr jukebox as that's more appropriate for memory
allocation failures.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux