Improper control of a resource through its lifetime in Linux kernel - CVE-2026-89697
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform a SETATTR operation without a mount write reference.
The vulnerability exists due to missing mount write reference acquisition in nfsd_proc_setattr() when processing a SETATTR request in the BOTH_TIME_SET branch. A remote attacker can submit a SETATTR request with both time attributes set to perform a SETATTR operation without a mount write reference.