Improper Validation of Specified Quantity in Input in Linux kernel - CVE-2026-89666
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to corrupt on-disk timestamp metadata.
The vulnerability exists due to improper validation of specified quantities in input in NFSv3 SETATTR and create operation handlers when processing client-supplied atime or mtime values with an out-of-range nanoseconds field. A remote attacker can send specially crafted NFSv3 SETATTR, CREATE, MKDIR, SYMLINK, or MKNOD requests to corrupt on-disk timestamp metadata.
Affected filesystems include ext4 and XFS with bigtime support.