SB2026091279 - Out-of-bounds write in Linux kernel nfsd
Published: September 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds write (CVE-ID: CVE-2026-89702)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to write beyond a reserved trace ring-buffer slot or disclose prior ring-buffer contents.
The vulnerability exists due to an out-of-bounds write in the nfsd_fh_verify and nfsd_fh_verify_err tracepoints when processing NFSv2/v3-over-UDP requests. A remote attacker can send an NFS/UDP request to write a server socket address into a zero-byte trace ring-buffer slot.
When the local server address is shorter than the remote address, unwritten bytes in the oversized slot can be exposed to trace consumers.
Remediation
Install update from vendor's website.