CVE-2026-89682
- EPSS 0.4%
- Veröffentlicht 11.09.2026 19:46:04
- Zuletzt bearbeitet 13.09.2026 07:17:34
In the Linux kernel, the following vulnerability has been resolved: nfsd: fix fcache_disposal UAF by inlining dispose state into nfsd_net nfsd_file_dispose_list_delayed() defers fput() to nfsd service threads via a per-net freeme queue, preventing ...
CVE-2026-89680
- EPSS 0.64%
- Veröffentlicht 11.09.2026 19:46:03
- Zuletzt bearbeitet 13.09.2026 07:17:33
In the Linux kernel, the following vulnerability has been resolved: nfsd: fix nfsd_file leak on inter-server COPY setup failure When nfsd4_setup_inter_ssc() fails, nfsd4_copy() returns nfserr_offload_denied directly, bypassing the out: label where ...
CVE-2026-89678
- EPSS 0.35%
- Veröffentlicht 11.09.2026 19:46:02
- Zuletzt bearbeitet 13.09.2026 07:17:33
In the Linux kernel, the following vulnerability has been resolved: nfsd: fix partial-write detection in nfsd_direct_write nfsd_direct_write() walks a list of write segments and, after each vfs_iocb_iter_write(), tries to detect a short write so th...
CVE-2026-89679
- EPSS 0.69%
- Veröffentlicht 11.09.2026 19:46:02
- Zuletzt bearbeitet 13.09.2026 07:17:33
In the Linux kernel, the following vulnerability has been resolved: nfsd: fix null dereference in nfsd4_setattr for deleg timestamp attrs When a SETATTR request includes FATTR4_WORD2_TIME_DELEG_ACCESS or FATTR4_WORD2_TIME_DELEG_MODIFY in the attrib...
CVE-2026-89677
- EPSS 0.41%
- Veröffentlicht 11.09.2026 19:46:01
- Zuletzt bearbeitet 13.09.2026 07:17:33
In the Linux kernel, the following vulnerability has been resolved: nfsd: fix possible fh_compose of wrong dentry in nfsd4_create_file() dentry_create() can hypothetically provide a different dentry than the one passed in. This could happen, for e...
CVE-2026-89676
- EPSS 0.45%
- Veröffentlicht 11.09.2026 19:46:00
- Zuletzt bearbeitet 21.09.2026 14:17:25
In the Linux kernel, the following vulnerability has been resolved: nfsd: fix stale s2s_cp_stateids IDR entry for async COPY For an async COPY, nfsd4_copy() called nfs4_init_copy_state() before dup_copy_fields(), so the s2s_cp_stateids IDR was poin...
CVE-2026-89675
- EPSS 0.45%
- Veröffentlicht 11.09.2026 19:45:59
- Zuletzt bearbeitet 13.09.2026 07:17:33
In the Linux kernel, the following vulnerability has been resolved: nfsd: fix UAF in async copy cancel and shutdown An async copy could be freed or used after free while a teardown caller (OFFLOAD_CANCEL, nfsd4_shutdown_copy, nfsd4_cancel_copy_by_s...
- EPSS 0.2%
- Veröffentlicht 11.09.2026 19:45:58
- Zuletzt bearbeitet 14.09.2026 13:19:19
In the Linux kernel, the following vulnerability has been resolved: nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo nfsd4_ff_encode_getdeviceinfo() computes the da_addr_body reservation as 16 + netid_len + addr_len, but the subsequent ...
CVE-2026-89674
- EPSS 0.46%
- Veröffentlicht 11.09.2026 19:45:58
- Zuletzt bearbeitet 14.09.2026 13:19:19
In the Linux kernel, the following vulnerability has been resolved: nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget The XDR buffer size calculation in nfsd4_ff_encode_layoutget() has multiple errors that can result in either an out-of...
CVE-2026-89672
- EPSS 0.52%
- Veröffentlicht 11.09.2026 19:45:57
- Zuletzt bearbeitet 14.09.2026 13:19:19
In the Linux kernel, the following vulnerability has been resolved: nfsd: gate nfs2 setacl by argp->mask The NFSACL v2 SETACL path shares the decoder convention used by its v3 sibling: nfsaclsvc_decode_setaclargs() fills in argp->acl_access only wh...