NULL pointer dereference in Linux kernel - CVE-2026-89679
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a null pointer dereference in nfsd4_setattr() when processing NFSv4 SETATTR requests containing delegation timestamp attributes and a one stateid. A remote attacker can send a specially crafted NFSv4 SETATTR request to cause a denial of service.
No delegation or prior state is required.