-

CVE-2026-89701

nfsd: validate nseconds in TIME_DELEG decode paths

In the Linux kernel, the following vulnerability has been resolved:

nfsd: validate nseconds in TIME_DELEG decode paths

The xdrgen-based TIME_DELEG_ACCESS and TIME_DELEG_MODIFY decode arms
store a raw uint32_t nseconds directly into tv_nsec without enforcing
nseconds < NSEC_PER_SEC. The legacy nfsd4_decode_nfstime4 has this
check but the TIME_DELEG paths do not. A malformed timespec can
propagate through notify_change() to disk.

Add range checks in both nfs4xdr.c (SETATTR path) and
nfs4callback.c (CB_GETATTR path).
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 6ae30d6eb26bce02c48c60074b4306270e2434c1
Version < 7e7b93da7fa2e77f977096251899d1410986adf6
Status affected
Version 6ae30d6eb26bce02c48c60074b4306270e2434c1
Version < 5eb489831a9fd4754f4baf26e6989efb66ce104c
Status affected
Version 6ae30d6eb26bce02c48c60074b4306270e2434c1
Version < 0f4a767340fad392bd656115b8752005518c9065
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.14
Status affected
Version 0
Version < 6.14
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.061
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/7e7b93da7fa2e77f977096251899d1410986adf6
https://git.kernel.org/stable/c/5eb489831a9fd4754f4baf26e6989efb66ce104c
https://git.kernel.org/stable/c/0f4a767340fad392bd656115b8752005518c9065