Out-of-bounds read in Linux kernel - CVE-2026-89691
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to disclose adjacent slab memory.
The vulnerability exists due to an out-of-bounds read in the RPC status dumpit handler when processing released NFSv4 compound arguments with a stale operation count. A local user can access the netlink status interface to disclose adjacent slab memory.
The exposure requires rq_status_counter to be stuck at an odd value.