CVE-2026-89667
- EPSS 0.51%
- Veröffentlicht 11.09.2026 19:45:53
- Zuletzt bearbeitet 21.09.2026 14:17:24
In the Linux kernel, the following vulnerability has been resolved: nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache The shrinker, GC worker, and fsnotify/lease callbacks can unhash an nfsd_file from the rhashtable and then ca...
CVE-2026-89665
- EPSS 0.54%
- Veröffentlicht 11.09.2026 19:45:52
- Zuletzt bearbeitet 14.09.2026 13:19:18
In the Linux kernel, the following vulnerability has been resolved: nfsd: reject out-of-range useconds in NFSv2 SETATTR/CREATE The NFSv2 sattr decoder converts the wire useconds to nanoseconds in svcxdr_decode_sattr(): iap->ia_atime.tv_nsec = tmp...
- EPSS 0.17%
- Veröffentlicht 11.09.2026 19:45:52
- Zuletzt bearbeitet 11.09.2026 20:19:53
In the Linux kernel, the following vulnerability has been resolved: nfsd: reject out-of-range nseconds in NFSv3 SETATTR and create ops A client can send an NFSv3 SETATTR, CREATE, MKDIR, SYMLINK or MKNOD carrying an atime or mtime whose nseconds fie...
CVE-2026-89664
- EPSS 0.49%
- Veröffentlicht 11.09.2026 19:45:51
- Zuletzt bearbeitet 13.09.2026 07:17:32
In the Linux kernel, the following vulnerability has been resolved: nfsd: release OPEN-decoded posix ACLs via op_release nfsd4_decode_createhow4() calls nfsd4_decode_fattr4(), which allocates refcounted struct posix_acl objects via posix_acl_alloc(...
CVE-2026-89663
- EPSS 0.4%
- Veröffentlicht 11.09.2026 19:45:50
- Zuletzt bearbeitet 14.09.2026 13:19:18
In the Linux kernel, the following vulnerability has been resolved: nfsd: revoke copy-notify stateids before dropping their reference Copy-notify stateids live in the s2s_cp_stateids IDR and on their parent stid's sc_cp_list, pinned by a single mem...
- EPSS 0.19%
- Veröffentlicht 11.09.2026 19:45:49
- Zuletzt bearbeitet 11.09.2026 20:19:52
In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent post-shutdown use-after-free in unlock_filesystem Writing a filesystem path to /proc/fs/nfsd/unlock_filesystem runs nfsd4_cancel_copy_by_sb() before nfsd_mutex is hel...
CVE-2026-89662
- EPSS 0.61%
- Veröffentlicht 11.09.2026 19:45:49
- Zuletzt bearbeitet 14.09.2026 13:19:18
In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent lock owner use-after-free during client teardown __destroy_client() releases a client's open owners, but a lock owner whose only reference is a blocked lock (nbl) sta...
CVE-2026-89660
- EPSS 0.59%
- Veröffentlicht 11.09.2026 19:45:48
- Zuletzt bearbeitet 21.09.2026 14:17:24
In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during admin state revocation A stateid holds only a bare pointer to its nfs4_client; a stateid reference does not pin it. The client survives ...
CVE-2026-89659
- EPSS 0.44%
- Veröffentlicht 11.09.2026 19:45:47
- Zuletzt bearbeitet 21.09.2026 14:17:24
In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during delegation revoke A delegation stateid holds only a bare pointer to its owning nfs4_client and does not keep it alive. The client surviv...
CVE-2026-89657
- EPSS 0.6%
- Veröffentlicht 11.09.2026 19:45:46
- Zuletzt bearbeitet 14.09.2026 13:19:18
In the Linux kernel, the following vulnerability has been resolved: libceph: validate OSD extent maps before cursor advance net/ceph/osd_client.c:osd_sparse_read() validates that the sparse-read data length matches the summed extent lengths, but it...