9.1

CVE-2026-89713

NFSD: check truncate permission under inode lock

In the Linux kernel, the following vulnerability has been resolved:

NFSD: check truncate permission under inode lock

nfsd_setattr() checks whether a size update needs NFSD_MAY_TRUNC
before it takes inode_lock(). The comparison uses the file size sampled
by that unlocked read, but the actual ATTR_SIZE update is applied later
under inode_lock() by notify_change().

This leaves a TOCTOU window for append-only files. If a client sends a
SETATTR that does not shrink the file at the time of the unlocked
sample, a concurrent append can extend the file before nfsd_setattr()
takes inode_lock(). notify_change() then applies a real truncation
without the NFSD_MAY_TRUNC check that rejects IS_APPEND(inode). The VFS
truncate syscall paths perform their own append-only checks before
calling notify_change(), so NFSD must make this decision against the
locked size it is about to change.

Split the write-count acquisition from the truncation permission check.
Keep get_write_access() before the locked setattr work, then recheck
whether the requested size is below i_size_read(inode) after inode_lock()
has been acquired and before notify_change(ATTR_SIZE). This also avoids
the plain unlocked inode->i_size load.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 783112f7401ff449d979530209b3f6c2594fdb4e
Version < 3afa17d93ba8c925f49370c816c6dae5112d8c24
Status affected
Version 783112f7401ff449d979530209b3f6c2594fdb4e
Version < d8352da196349182e1afd5a93308256cddc0a97d
Status affected
Version 783112f7401ff449d979530209b3f6c2594fdb4e
Version < 44086254479035de42ca3d286ecf25521d4e6325
Status affected
Version 783112f7401ff449d979530209b3f6c2594fdb4e
Version < b778e0e0a16759f22a70579c3cf8d254a40d4a7f
Status affected
Version 604a3c407026d6162d15300478e63f901e435efc
Status affected
Version cc4d5dc73841b98d33cdfb9822d70b0aac4beca5
Status affected
Version 3ee4f442e5b37a537297b812557b1163f96b5399
Status affected
Version a3c6cbc4eac4473ed5461d5faae2794d3e5c0e44
Status affected
Version 982898d7f97a35447403c3fcecc0d96c646ce101
Status affected
Version 3.2.89
Version < 3.3
Status affected
Version 3.16.44
Version < 3.17
Status affected
Version 4.4.53
Version < 4.5
Status affected
Version 4.9.14
Version < 4.10
Status affected
Version 4.10.2
Version < 4.11
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.11
Status affected
Version 0
Version < 4.11
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.6% 0.47
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/3afa17d93ba8c925f49370c816c6dae5112d8c24
https://git.kernel.org/stable/c/d8352da196349182e1afd5a93308256cddc0a97d
https://git.kernel.org/stable/c/44086254479035de42ca3d286ecf25521d4e6325
https://git.kernel.org/stable/c/b778e0e0a16759f22a70579c3cf8d254a40d4a7f