Improper Handling of Length Parameter Inconsistency in Linux kernel - CVE-2026-89673
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose stale reply-page content.
The vulnerability exists due to an incorrect XDR padding calculation in nfsd4_ff_encode_getdeviceinfo() when encoding flexfile GETDEVICEINFO replies. A remote attacker can send a GETDEVICEINFO request to disclose stale reply-page content.
The incorrect declared address-body length can also mis-align decoding of the subsequent version list.