CVE-2026-89697
- EPSS 0.6%
- Veröffentlicht 11.09.2026 19:46:15
- Zuletzt bearbeitet 14.09.2026 13:19:20
In the Linux kernel, the following vulnerability has been resolved: nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr() The BOTH_TIME_SET branch calls fh_verify() early so setattr_prepare() can inspect the dentry. This cause...
CVE-2026-89695
- EPSS 0.49%
- Veröffentlicht 11.09.2026 19:46:14
- Zuletzt bearbeitet 13.09.2026 07:17:35
In the Linux kernel, the following vulnerability has been resolved: nfsd: cap decoded POSIX ACL count to bound sort cost nfsd4_decode_posixacl() reads a u32 entry count off the wire and passes it straight to posix_acl_alloc() and sort_pacl_range()....
- EPSS 0.2%
- Veröffentlicht 11.09.2026 19:46:13
- Zuletzt bearbeitet 14.09.2026 13:19:19
In the Linux kernel, the following vulnerability has been resolved: nfsd: check client ownership when cancelling a copy-notify stateid On the OFFLOAD_CANCEL path (clp != NULL), manage_cpntf_state() freed the target cpntf state without checking owne...
CVE-2026-89692
- EPSS 0.43%
- Veröffentlicht 11.09.2026 19:46:12
- Zuletzt bearbeitet 13.09.2026 07:17:35
In the Linux kernel, the following vulnerability has been resolved: nfsd: clear CALLBACK_RUNNING on failed delegation recall queue nfsd_break_one_deleg() sets NFSD4_CALLBACK_RUNNING via test_and_set_bit at entry to serialize recall work, then calls...
- EPSS 0.17%
- Veröffentlicht 11.09.2026 19:46:12
- Zuletzt bearbeitet 21.09.2026 14:17:25
In the Linux kernel, the following vulnerability has been resolved: nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create() nfsd4_create() stores the return value of nfsd4_acl_to_attr() in status, but the switch(create->cr_type) block uncond...
CVE-2026-89691
- EPSS 0.13%
- Veröffentlicht 11.09.2026 19:46:11
- Zuletzt bearbeitet 13.09.2026 07:17:34
In the Linux kernel, the following vulnerability has been resolved: nfsd: clear opcnt on compound arg release to prevent OOB read nfsd4_release_compoundargs() resets args->ops to the inline iops[8] array when the dynamically-allocated ops buffer is...
CVE-2026-89690
- EPSS 0.16%
- Veröffentlicht 11.09.2026 19:46:10
- Zuletzt bearbeitet 13.09.2026 07:17:34
In the Linux kernel, the following vulnerability has been resolved: nfsd: defer vfree of compound ops to fix rpc_status UAF The rpc_status netlink dumpit walks every in-flight svc_rqst under rcu_read_lock and, for NFSv4 requests, reads opnums out o...
CVE-2026-89688
- EPSS 0.61%
- Veröffentlicht 11.09.2026 19:46:09
- Zuletzt bearbeitet 13.09.2026 07:17:34
In the Linux kernel, the following vulnerability has been resolved: nfsd: drop the stateid, not the stateowner, on seqid_op replay retry In nfs4_preprocess_seqid_op() the stateid is obtained from nfsd4_lookup_stateid(), which holds a reference on t...
CVE-2026-89689
- EPSS 0.61%
- Veröffentlicht 11.09.2026 19:46:09
- Zuletzt bearbeitet 13.09.2026 07:17:34
In the Linux kernel, the following vulnerability has been resolved: nfsd: don't free session slots that are still in use nfsd4_sequence() can free the very slot it is currently processing. When the session shrinker has reduced se_target_maxslots be...
CVE-2026-89687
- EPSS 0.47%
- Veröffentlicht 11.09.2026 19:46:08
- Zuletzt bearbeitet 13.09.2026 07:17:34
In the Linux kernel, the following vulnerability has been resolved: nfsd: ensure nfsd_file_do_acquire() does not use a non-opened file ->atomic_open is permitted to return success without actually opening the file. It indicates this by calling fin...