Out-of-bounds write in Linux kernel - CVE-2026-89702

 

Out-of-bounds write in Linux kernel - CVE-2026-89702

Published: September 12, 2026


Vulnerability identifier: #VU149102
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-89702
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to write beyond a reserved trace ring-buffer slot or disclose prior ring-buffer contents.

The vulnerability exists due to an out-of-bounds write in the nfsd_fh_verify and nfsd_fh_verify_err tracepoints when processing NFSv2/v3-over-UDP requests. A remote attacker can send an NFS/UDP request to write a server socket address into a zero-byte trace ring-buffer slot.

When the local server address is shorter than the remote address, unwritten bytes in the oversized slot can be exposed to trace consumers.


Affected software

Linux kernel

How to mitigate CVE-2026-89702

Install security update from vendor's repository.


External References

Related Security Bulletins