CVE-2026-89708
- EPSS 0.44%
- Veröffentlicht 11.09.2026 19:46:24
- Zuletzt bearbeitet 21.09.2026 14:17:25
In the Linux kernel, the following vulnerability has been resolved: nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown After a DESTROY_SESSION the per-session teardown path can free a session while rpciod still holds an infli...
CVE-2026-89709
- EPSS 0.33%
- Veröffentlicht 11.09.2026 19:46:24
- Zuletzt bearbeitet 13.09.2026 07:17:36
In the Linux kernel, the following vulnerability has been resolved: lockd, nfsd: RCU-protect nlmsvc_ops dispatch nlmsvc_ops is published by nfsd_lockd_init() and cleared by nfsd_lockd_shutdown() with plain stores, while lockd dereferences it unguar...
CVE-2026-89707
- EPSS 0.6%
- Veröffentlicht 11.09.2026 19:46:23
- Zuletzt bearbeitet 14.09.2026 13:19:20
In the Linux kernel, the following vulnerability has been resolved: nfsd: release path refs on follow_down() error nfsd_cross_mnt() initializes a local struct path with mntget() and dget() before calling follow_down(). On a negative return the erro...
CVE-2026-89706
- EPSS 0.44%
- Veröffentlicht 11.09.2026 19:46:22
- Zuletzt bearbeitet 14.09.2026 13:19:20
In the Linux kernel, the following vulnerability has been resolved: nfsd: Reset write verifier when async COPY writeback fails Async COPY captures nn->writeverf at request time and reports it to the client via CB_OFFLOAD after the worker kthread co...
CVE-2026-89704
- EPSS 0.44%
- Veröffentlicht 11.09.2026 19:46:21
- Zuletzt bearbeitet 14.09.2026 13:19:20
In the Linux kernel, the following vulnerability has been resolved: nfsd: sample writeback error cursor before async COPY loop _nfsd_copy_file_range() samples dst->f_wb_err into "since" after the copy loop, then uses it to detect writeback errors v...
CVE-2026-89702
- EPSS 0.46%
- Veröffentlicht 11.09.2026 19:46:19
- Zuletzt bearbeitet 13.09.2026 07:17:35
In the Linux kernel, the following vulnerability has been resolved: nfsd: size fh_verify server sockaddr slot by xpt_locallen The nfsd_fh_verify and nfsd_fh_verify_err tracepoints declare the server sockaddr slot sized by xpt_remotelen but fill it ...
CVE-2026-89699
- EPSS 0.45%
- Veröffentlicht 11.09.2026 19:46:17
- Zuletzt bearbeitet 14.09.2026 13:19:20
In the Linux kernel, the following vulnerability has been resolved: nfsd: validate symlink target length in NFSv4 CREATE nfsd4_decode_create() accepts an unbounded cr_datalen from the wire for NF4LNK symlink targets, allowing a client to force a km...
CVE-2026-89696
- EPSS 0.67%
- Veröffentlicht 11.09.2026 19:46:15
- Zuletzt bearbeitet 14.09.2026 13:19:19
In the Linux kernel, the following vulnerability has been resolved: nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref When CONFIG_NFSD_V4_2_INTER_SSC is enabled, nfsd4_putfh() can return success with fh_dentry and fh_export both ...
CVE-2026-89697
- EPSS 0.6%
- Veröffentlicht 11.09.2026 19:46:15
- Zuletzt bearbeitet 14.09.2026 13:19:20
In the Linux kernel, the following vulnerability has been resolved: nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr() The BOTH_TIME_SET branch calls fh_verify() early so setattr_prepare() can inspect the dentry. This cause...
- EPSS 0.2%
- Veröffentlicht 11.09.2026 19:46:13
- Zuletzt bearbeitet 14.09.2026 13:19:19
In the Linux kernel, the following vulnerability has been resolved: nfsd: check client ownership when cancelling a copy-notify stateid On the OFFLOAD_CANCEL path (clp != NULL), manage_cpntf_state() freed the target cpntf state without checking owne...