Improper input validation in Linux kernel - CVE-2026-89701
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to write malformed timestamps to disk.
The vulnerability exists due to improper input validation in the TIME_DELEG_ACCESS and TIME_DELEG_MODIFY decode paths in nfs4xdr.c and nfs4callback.c when decoding TIME_DELEG timestamp attributes. A remote attacker can submit malformed TIME_DELEG timestamp attributes to write malformed timestamps to disk.