Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-89674

nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget
Back to all
CVE

CVE-2026-89674

nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget

In the Linux kernel, the following vulnerability has been resolved:

nfsd: fix XDR length calculation in nfsd4ffencode_layoutget

The XDR buffer size calculation in nfsd4ffencode_layoutget() has

multiple errors that can result in either an out-of-bounds write or

leaking uninitialized kernel memory to the client:

  • fh_len doesn't account for XDR padding on the file handle data
  • uid and gid lengths use "8 + len" but xdrencodeopaque() actually

   writes "4 + xdralignsize(len)" bytes

  • dslen omits the flags and statscollect_hint fields (8 bytes),

   while len's header constant overestimates by 8 bytes -- these

   partially cancel but leave a net mismatch

The worst case occurs with short strings (e.g. uid=0, gid=0 with an

odd-sized file handle), where the function writes up to 5 bytes past

the reserved XDR buffer. Conversely, when string lengths happen to be

4-byte aligned, the reservation is too large and stale buffer content

is sent to the client.

Fix this by breaking out every encoded field explicitly in the ds_len

calculation, using xdralignsize() for all variable-length opaque

fields, and correcting the header constants.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/0380129b1373c437eb35401a174671c8888f4b80, https://git.kernel.org/stable/c/29e4478e2ed5a227e8f0c33cacb91bf227cedd47, https://git.kernel.org/stable/c/3a7fd224df0fbb42167eb1b77be45d72fe0b1098, https://git.kernel.org/stable/c/65a72b721943618eeb3a41c8b36e915591f3f83f, https://git.kernel.org/stable/c/bee826c00ac900473f91306f1f3e5a5a81fd4a74, https://git.kernel.org/stable/c/c81cef6a805dec266c10fc4f83c93d6fcf1a2b43, https://git.kernel.org/stable/c/e7d9d23ecd9172f05b09bb678ff22db8e361c428, https://git.kernel.org/stable/c/f9868174af49d207fbaf0c5e055d088a983684af, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89674.json, https://nvd.nist.gov/vuln/detail/CVE-2026-89674, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00514%
EPSS Percentile
0.41944%
Introduced Version
9b9960a0ca4773e21c4b153ed355583946346b25,4.8.0,5.11.0,5.16.0,6.2.0,6.7.0,6.13.0,6.19.0,0
Fix Available
f9868174af49d207fbaf0c5e055d088a983684af,5.10.270,5.15.221,6.1.188,6.6.157,6.12.109,6.18.50,7.2.4,6.12.111-1~deb12u1,6.12.111-1,0:6.12.0-207.111.5.1.el10uek,0:6.12.0-207.111.5.1.el9uek

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading