-

CVE-2026-89698

nfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage

In the Linux kernel, the following vulnerability has been resolved:

nfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage

struct nfsd_genl_rqstp declares rq_daddr and rq_saddr as plain
"struct sockaddr" (16 bytes). When an IPv6 NFS client is connected,
nfsd_genl_rpc_status_compose_msg() casts these fields to
"struct sockaddr_in6 *" (28 bytes) and reads sin6_addr at offset 8..24,
which extends 8 bytes past the end of the 16-byte sockaddr field into
the adjacent rq_flags member. The 16-byte nla_put_in6_addr then ships 8
bytes of truncated IPv6 address followed by 8 bytes of rq_flags to
userspace via the NFSD_A_RPC_STATUS_SADDR6/DADDR6 netlink attributes.

This is reachable by any unprivileged process in the network namespace
because NFSD_CMD_RPC_STATUS_GET uses GENL_CMD_CAP_DUMP without
GENL_ADMIN_PERM.

Fix by widening rq_daddr and rq_saddr to struct sockaddr_storage so the
IPv6 casts operate within bounds, copying sizeof(struct sockaddr_storage)
bytes in the memcpy calls so the full address is captured, and
zero-initializing the genl_rqstp stack variable to prevent leaking
uninitialized tail bytes through netlink.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version bd9d6a3efa9709e653aafbeb859289feccb8e70c
Version < 9a2e791639a1c5cac3f219b0d2632835d8f88d27
Status affected
Version bd9d6a3efa9709e653aafbeb859289feccb8e70c
Version < 03c512f22d3fbe7a3767d6df5e3d88b8e7c105e5
Status affected
Version bd9d6a3efa9709e653aafbeb859289feccb8e70c
Version < dcb69ad0dafb4a24b825183bb94055d5be8a10bd
Status affected
Version bd9d6a3efa9709e653aafbeb859289feccb8e70c
Version < a99d720ed2a5258564e5e9d5f39f3184a030d354
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.7
Status affected
Version 0
Version < 6.7
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.097
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/03c512f22d3fbe7a3767d6df5e3d88b8e7c105e5
https://git.kernel.org/stable/c/dcb69ad0dafb4a24b825183bb94055d5be8a10bd
https://git.kernel.org/stable/c/a99d720ed2a5258564e5e9d5f39f3184a030d354
https://git.kernel.org/stable/c/9a2e791639a1c5cac3f219b0d2632835d8f88d27