Inefficient Algorithmic Complexity in Linux kernel - CVE-2026-89695
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient algorithmic complexity in nfsd4_decode_posixacl() when processing an NFSv4 POSIX ACL with a user-controlled entry count. A remote attacker can submit an ACL with a large entry count to cause a denial of service.
The entry count is used by a quadratic bubble sort during NFS server compound request processing.