DEBIAN-CVE-2026-89713
In the Linux kernel, the following vulnerability has been resolved: NFSD: check truncate permission under inode lock nfsdsetattr() checks whether a size update needs NFSDMAYTRUNC before it takes inodelock(). The comparison uses the file size sampled by that unlocked read, but the actual ATTRSIZE update is applied later under inodelock() by notifychange(). This leaves a TOCTOU window for append-only files. If a client sends a SETATTR that does not shrink the file at the time of the unlocked sample, a concurrent append can extend the file before nfsdsetattr() takes inodelock(). notifychange() then applies a real truncation without the NFSDMAYTRUNC check that rejects ISAPPEND(inode). The VFS truncate syscall paths perform their own append-only checks before calling notifychange(), so NFSD must make this decision against the locked size it is about to change. Split the write-count acquisition from the truncation permission check. Keep getwriteaccess() before the locked setattr work, then recheck whether the requested size is below isizeread(inode) after inodelock() has been acquired and before notifychange(ATTRSIZE). This also avoids the plain unlocked inode->isize load.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://security-tracker.debian.org/tracker/CVE-2026-89713