- EPSS 0.17%
- Veröffentlicht 11.09.2026 19:46:18
- Zuletzt bearbeitet 21.09.2026 14:17:25
In the Linux kernel, the following vulnerability has been resolved: nfsd: validate sockaddr length per family in listener_set nfsd_sock_nl_policy declares NFSD_A_SOCK_ADDR as a bare NLA_BINARY attribute with no minimum length. A CAP_NET_ADMIN calle...
- EPSS 0.17%
- Veröffentlicht 11.09.2026 19:46:18
- Zuletzt bearbeitet 11.09.2026 20:19:57
In the Linux kernel, the following vulnerability has been resolved: nfsd: validate nseconds in TIME_DELEG decode paths The xdrgen-based TIME_DELEG_ACCESS and TIME_DELEG_MODIFY decode arms store a raw uint32_t nseconds directly into tv_nsec without ...
CVE-2026-89699
- EPSS 0.45%
- Veröffentlicht 11.09.2026 19:46:17
- Zuletzt bearbeitet 14.09.2026 13:19:20
In the Linux kernel, the following vulnerability has been resolved: nfsd: validate symlink target length in NFSv4 CREATE nfsd4_decode_create() accepts an unbounded cr_datalen from the wire for NF4LNK symlink targets, allowing a client to force a km...
- EPSS 0.2%
- Veröffentlicht 11.09.2026 19:46:16
- Zuletzt bearbeitet 21.09.2026 14:17:25
In the Linux kernel, the following vulnerability has been resolved: nfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage struct nfsd_genl_rqstp declares rq_daddr and rq_saddr as plain "struct sockaddr" (16 bytes). When an IPv6 NFS client ...
CVE-2026-89696
- EPSS 0.67%
- Veröffentlicht 11.09.2026 19:46:15
- Zuletzt bearbeitet 14.09.2026 13:19:19
In the Linux kernel, the following vulnerability has been resolved: nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref When CONFIG_NFSD_V4_2_INTER_SSC is enabled, nfsd4_putfh() can return success with fh_dentry and fh_export both ...
CVE-2026-89697
- EPSS 0.6%
- Veröffentlicht 11.09.2026 19:46:15
- Zuletzt bearbeitet 14.09.2026 13:19:20
In the Linux kernel, the following vulnerability has been resolved: nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr() The BOTH_TIME_SET branch calls fh_verify() early so setattr_prepare() can inspect the dentry. This cause...
CVE-2026-89695
- EPSS 0.49%
- Veröffentlicht 11.09.2026 19:46:14
- Zuletzt bearbeitet 13.09.2026 07:17:35
In the Linux kernel, the following vulnerability has been resolved: nfsd: cap decoded POSIX ACL count to bound sort cost nfsd4_decode_posixacl() reads a u32 entry count off the wire and passes it straight to posix_acl_alloc() and sort_pacl_range()....
- EPSS 0.2%
- Veröffentlicht 11.09.2026 19:46:13
- Zuletzt bearbeitet 14.09.2026 13:19:19
In the Linux kernel, the following vulnerability has been resolved: nfsd: check client ownership when cancelling a copy-notify stateid On the OFFLOAD_CANCEL path (clp != NULL), manage_cpntf_state() freed the target cpntf state without checking owne...
CVE-2026-89692
- EPSS 0.43%
- Veröffentlicht 11.09.2026 19:46:12
- Zuletzt bearbeitet 13.09.2026 07:17:35
In the Linux kernel, the following vulnerability has been resolved: nfsd: clear CALLBACK_RUNNING on failed delegation recall queue nfsd_break_one_deleg() sets NFSD4_CALLBACK_RUNNING via test_and_set_bit at entry to serialize recall work, then calls...
- EPSS 0.17%
- Veröffentlicht 11.09.2026 19:46:12
- Zuletzt bearbeitet 21.09.2026 14:17:25
In the Linux kernel, the following vulnerability has been resolved: nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create() nfsd4_create() stores the return value of nfsd4_acl_to_attr() in status, but the switch(create->cr_type) block uncond...