Out-of-bounds read in Linux kernel - CVE-2026-89705
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to read beyond the bounds of an inline operations array.
The vulnerability exists due to improper synchronization in nfsd_dispatch() when processing NFS requests that follow cache-hit, drop, or encode-error paths. A remote attacker can leave rq_status_counter in an odd state while nfsd_nl_rpc_status_get_dumpit() reads request fields to read beyond the bounds of an inline operations array.
Exploitation requires concurrent access by the lockless status dump reader while request fields are being mutated.