7.1

CVE-2026-89691

nfsd: clear opcnt on compound arg release to prevent OOB read

In the Linux kernel, the following vulnerability has been resolved:

nfsd: clear opcnt on compound arg release to prevent OOB read

nfsd4_release_compoundargs() resets args->ops to the inline iops[8]
array when the dynamically-allocated ops buffer is freed, but leaves
args->opcnt at its original value (which can be up to 200 for NFSv4.1+
compounds).

If rq_status_counter is stuck at an odd value (which can happen when
nfsd_dispatch() hits an error path after setting it odd), the RPC
status dumpit handler reads min(opcnt, 16) entries from args->ops[].
Since iops only has 8 elements and is the last field in struct
nfsd4_compoundargs, reading indices 8-15 accesses adjacent slab memory
and leaks it to userspace via netlink.

Zero opcnt unconditionally in nfsd4_release_compoundargs() so stale
compound metadata is never exposed through the status interface.

[ cel: Remove the kvfree_rcu_mightsleep() sleep from the exposure window ]
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version bd9d6a3efa9709e653aafbeb859289feccb8e70c
Version < 58bcdfb2b2e412088839ae740b1a95154dc0b8d0
Status affected
Version bd9d6a3efa9709e653aafbeb859289feccb8e70c
Version < e879148867bd4c4cac42e063ffaffa187dddc6fe
Status affected
Version bd9d6a3efa9709e653aafbeb859289feccb8e70c
Version < c1a4f7b1848f95302df598217e1c7a1410c2d0c5
Status affected
Version bd9d6a3efa9709e653aafbeb859289feccb8e70c
Version < ae4c38555e81563b8dc5eae55ffd70f0ea97aa5a
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.7
Status affected
Version 0
Version < 6.7
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.025
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/58bcdfb2b2e412088839ae740b1a95154dc0b8d0
https://git.kernel.org/stable/c/e879148867bd4c4cac42e063ffaffa187dddc6fe
https://git.kernel.org/stable/c/c1a4f7b1848f95302df598217e1c7a1410c2d0c5
https://git.kernel.org/stable/c/ae4c38555e81563b8dc5eae55ffd70f0ea97aa5a