CVE-2026-89707
- EPSS 0.6%
- Veröffentlicht 11.09.2026 19:46:23
- Zuletzt bearbeitet 14.09.2026 13:19:20
In the Linux kernel, the following vulnerability has been resolved: nfsd: release path refs on follow_down() error nfsd_cross_mnt() initializes a local struct path with mntget() and dget() before calling follow_down(). On a negative return the erro...
CVE-2026-89706
- EPSS 0.44%
- Veröffentlicht 11.09.2026 19:46:22
- Zuletzt bearbeitet 14.09.2026 13:19:20
In the Linux kernel, the following vulnerability has been resolved: nfsd: Reset write verifier when async COPY writeback fails Async COPY captures nn->writeverf at request time and reports it to the client via CB_OFFLOAD after the worker kthread co...
CVE-2026-89704
- EPSS 0.44%
- Veröffentlicht 11.09.2026 19:46:21
- Zuletzt bearbeitet 14.09.2026 13:19:20
In the Linux kernel, the following vulnerability has been resolved: nfsd: sample writeback error cursor before async COPY loop _nfsd_copy_file_range() samples dst->f_wb_err into "since" after the copy loop, then uses it to detect writeback errors v...
CVE-2026-89705
- EPSS 0.15%
- Veröffentlicht 11.09.2026 19:46:21
- Zuletzt bearbeitet 13.09.2026 07:17:36
In the Linux kernel, the following vulnerability has been resolved: nfsd: restore rq_status_counter to even on all nfsd_dispatch() exit paths nfsd_dispatch() sets rq_status_counter to an odd value once a request has been decoded, and back to an eve...
CVE-2026-89703
- EPSS 0.61%
- Veröffentlicht 11.09.2026 19:46:20
- Zuletzt bearbeitet 13.09.2026 07:17:35
In the Linux kernel, the following vulnerability has been resolved: nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_stid for delegations nfsd4_drop_revoked_stid() handles FREE_STATEID for admin-revoked delegations but does not set SC_STATUS_FREED b...
CVE-2026-89702
- EPSS 0.46%
- Veröffentlicht 11.09.2026 19:46:19
- Zuletzt bearbeitet 13.09.2026 07:17:35
In the Linux kernel, the following vulnerability has been resolved: nfsd: size fh_verify server sockaddr slot by xpt_locallen The nfsd_fh_verify and nfsd_fh_verify_err tracepoints declare the server sockaddr slot sized by xpt_remotelen but fill it ...
- EPSS 0.17%
- Veröffentlicht 11.09.2026 19:46:18
- Zuletzt bearbeitet 21.09.2026 14:17:25
In the Linux kernel, the following vulnerability has been resolved: nfsd: validate sockaddr length per family in listener_set nfsd_sock_nl_policy declares NFSD_A_SOCK_ADDR as a bare NLA_BINARY attribute with no minimum length. A CAP_NET_ADMIN calle...
CVE-2026-89699
- EPSS 0.45%
- Veröffentlicht 11.09.2026 19:46:17
- Zuletzt bearbeitet 14.09.2026 13:19:20
In the Linux kernel, the following vulnerability has been resolved: nfsd: validate symlink target length in NFSv4 CREATE nfsd4_decode_create() accepts an unbounded cr_datalen from the wire for NF4LNK symlink targets, allowing a client to force a km...
- EPSS 0.2%
- Veröffentlicht 11.09.2026 19:46:16
- Zuletzt bearbeitet 21.09.2026 14:17:25
In the Linux kernel, the following vulnerability has been resolved: nfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage struct nfsd_genl_rqstp declares rq_daddr and rq_saddr as plain "struct sockaddr" (16 bytes). When an IPv6 NFS client ...
CVE-2026-89696
- EPSS 0.67%
- Veröffentlicht 11.09.2026 19:46:15
- Zuletzt bearbeitet 14.09.2026 13:19:19
In the Linux kernel, the following vulnerability has been resolved: nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref When CONFIG_NFSD_V4_2_INTER_SSC is enabled, nfsd4_putfh() can return success with fh_dentry and fh_export both ...