NULL pointer dereference in Linux kernel - CVE-2026-89696
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a null pointer dereference in the NFS server compound request dispatch loop when processing a crafted NFSv4 COMPOUND request involving an inter-SSC COPY operation. A remote attacker can send a crafted NFSv4 COMPOUND request with an operation between a foreign PUTFH and SAVEFH to cause a denial of service.
Only systems with CONFIG_NFSD_V4_2_INTER_SSC enabled are affected.