Out-of-bounds write in Linux kernel - CVE-2026-89702
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to write beyond a reserved trace ring-buffer slot or disclose prior ring-buffer contents.
The vulnerability exists due to an out-of-bounds write in the nfsd_fh_verify and nfsd_fh_verify_err tracepoints when processing NFSv2/v3-over-UDP requests. A remote attacker can send an NFS/UDP request to write a server socket address into a zero-byte trace ring-buffer slot.
When the local server address is shorter than the remote address, unwritten bytes in the oversized slot can be exposed to trace consumers.