SB2026091279 - Out-of-bounds write in Linux kernel nfsd



SB2026091279 - Out-of-bounds write in Linux kernel nfsd

Published: September 12, 2026

Security Bulletin ID SB2026091279
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Out-of-bounds write (CVE-ID: CVE-2026-89702)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to write beyond a reserved trace ring-buffer slot or disclose prior ring-buffer contents.

The vulnerability exists due to an out-of-bounds write in the nfsd_fh_verify and nfsd_fh_verify_err tracepoints when processing NFSv2/v3-over-UDP requests. A remote attacker can send an NFS/UDP request to write a server socket address into a zero-byte trace ring-buffer slot.

When the local server address is shorter than the remote address, unwritten bytes in the oversized slot can be exposed to trace consumers.


Remediation

Install update from vendor's website.