-
CVE-2026-89698
- EPSS 0.2%
- Veröffentlicht 11.09.2026 19:46:16
- Zuletzt bearbeitet 21.09.2026 14:17:25
- Erkennungen
nfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage
In the Linux kernel, the following vulnerability has been resolved: nfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage struct nfsd_genl_rqstp declares rq_daddr and rq_saddr as plain "struct sockaddr" (16 bytes). When an IPv6 NFS client is connected, nfsd_genl_rpc_status_compose_msg() casts these fields to "struct sockaddr_in6 *" (28 bytes) and reads sin6_addr at offset 8..24, which extends 8 bytes past the end of the 16-byte sockaddr field into the adjacent rq_flags member. The 16-byte nla_put_in6_addr then ships 8 bytes of truncated IPv6 address followed by 8 bytes of rq_flags to userspace via the NFSD_A_RPC_STATUS_SADDR6/DADDR6 netlink attributes. This is reachable by any unprivileged process in the network namespace because NFSD_CMD_RPC_STATUS_GET uses GENL_CMD_CAP_DUMP without GENL_ADMIN_PERM. Fix by widening rq_daddr and rq_saddr to struct sockaddr_storage so the IPv6 casts operate within bounds, copying sizeof(struct sockaddr_storage) bytes in the memcpy calls so the full address is captured, and zero-initializing the genl_rqstp stack variable to prevent leaking uninitialized tail bytes through netlink.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
bd9d6a3efa9709e653aafbeb859289feccb8e70c
Version <
9a2e791639a1c5cac3f219b0d2632835d8f88d27
Status
affected
Version
bd9d6a3efa9709e653aafbeb859289feccb8e70c
Version <
03c512f22d3fbe7a3767d6df5e3d88b8e7c105e5
Status
affected
Version
bd9d6a3efa9709e653aafbeb859289feccb8e70c
Version <
dcb69ad0dafb4a24b825183bb94055d5be8a10bd
Status
affected
Version
bd9d6a3efa9709e653aafbeb859289feccb8e70c
Version <
a99d720ed2a5258564e5e9d5f39f3184a030d354
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.7
Status
affected
Version
0
Version <
6.7
Status
unaffected
Version <=
6.12.*
Version
6.12.111
Status
unaffected
Version <=
6.18.*
Version
6.18.51
Status
unaffected
Version <=
7.2.*
Version
7.2.4
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.097 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/03c512f22d3fbe7a3767d6df5e3d88b8e7c105e5
https://git.kernel.org/stable/c/dcb69ad0dafb4a24b825183bb94055d5be8a10bd
https://git.kernel.org/stable/c/a99d720ed2a5258564e5e9d5f39f3184a030d354
https://git.kernel.org/stable/c/9a2e791639a1c5cac3f219b0d2632835d8f88d27