Integer overflow in Linux kernel - CVE-2026-89665
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause improper filesystem timestamp handling.
The vulnerability exists due to an integer overflow in the NFSv2 sattr decoder in svcxdr_decode_sattr() when decoding NFSv2 SETATTR or CREATE time attributes. A remote attacker can send a crafted NFSv2 request containing an out-of-range useconds value to cause improper filesystem timestamp handling.
The overflow affects 32-bit ILP32 platforms.