CVE-2026-89676
- EPSS 0.45%
- Veröffentlicht 11.09.2026 19:46:00
- Zuletzt bearbeitet 21.09.2026 14:17:25
In the Linux kernel, the following vulnerability has been resolved: nfsd: fix stale s2s_cp_stateids IDR entry for async COPY For an async COPY, nfsd4_copy() called nfs4_init_copy_state() before dup_copy_fields(), so the s2s_cp_stateids IDR was poin...
CVE-2026-89675
- EPSS 0.45%
- Veröffentlicht 11.09.2026 19:45:59
- Zuletzt bearbeitet 13.09.2026 07:17:33
In the Linux kernel, the following vulnerability has been resolved: nfsd: fix UAF in async copy cancel and shutdown An async copy could be freed or used after free while a teardown caller (OFFLOAD_CANCEL, nfsd4_shutdown_copy, nfsd4_cancel_copy_by_s...
- EPSS 0.2%
- Veröffentlicht 11.09.2026 19:45:58
- Zuletzt bearbeitet 14.09.2026 13:19:19
In the Linux kernel, the following vulnerability has been resolved: nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo nfsd4_ff_encode_getdeviceinfo() computes the da_addr_body reservation as 16 + netid_len + addr_len, but the subsequent ...
CVE-2026-89674
- EPSS 0.46%
- Veröffentlicht 11.09.2026 19:45:58
- Zuletzt bearbeitet 14.09.2026 13:19:19
In the Linux kernel, the following vulnerability has been resolved: nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget The XDR buffer size calculation in nfsd4_ff_encode_layoutget() has multiple errors that can result in either an out-of...
CVE-2026-89672
- EPSS 0.52%
- Veröffentlicht 11.09.2026 19:45:57
- Zuletzt bearbeitet 14.09.2026 13:19:19
In the Linux kernel, the following vulnerability has been resolved: nfsd: gate nfs2 setacl by argp->mask The NFSACL v2 SETACL path shares the decoder convention used by its v3 sibling: nfsaclsvc_decode_setaclargs() fills in argp->acl_access only wh...
CVE-2026-89671
- EPSS 0.49%
- Veröffentlicht 11.09.2026 19:45:56
- Zuletzt bearbeitet 14.09.2026 13:19:19
In the Linux kernel, the following vulnerability has been resolved: nfsd: gate nfs3 setacl by argp->mask nfsd3_proc_setacl() calls set_posix_acl() unconditionally for both ACL_TYPE_ACCESS and ACL_TYPE_DEFAULT, passing argp->acl_access and argp->acl...
CVE-2026-89669
- EPSS 0.61%
- Veröffentlicht 11.09.2026 19:45:55
- Zuletzt bearbeitet 14.09.2026 13:19:18
In the Linux kernel, the following vulnerability has been resolved: nfsd: initialize copy-notify stateid before publishing it nfsd4_copy_notify() finished initializing the cpntf state after nfs4_alloc_init_cpntf_state() had already linked it into t...
CVE-2026-89670
- EPSS 0.16%
- Veröffentlicht 11.09.2026 19:45:55
- Zuletzt bearbeitet 13.09.2026 07:17:32
In the Linux kernel, the following vulnerability has been resolved: nfsd: hold rcu across localio cmpxchg retry nfsd_file objects are freed via call_rcu (filecache.c:296), and nfsd_file_slab is created without SLAB_TYPESAFE_BY_RCU (KMEM_CACHE(nfsd_...
CVE-2026-89668
- EPSS 0.17%
- Veröffentlicht 11.09.2026 19:45:54
- Zuletzt bearbeitet 13.09.2026 07:17:32
In the Linux kernel, the following vulnerability has been resolved: nfsd: move nfsd_debugfs_init() after nfsd4_init_slabs() in init_nfsd() nfsd_debugfs_init() runs before nfsd4_init_slabs() in init_nfsd(). If the slab allocation fails, the bare "re...
CVE-2026-89667
- EPSS 0.51%
- Veröffentlicht 11.09.2026 19:45:53
- Zuletzt bearbeitet 21.09.2026 14:17:24
In the Linux kernel, the following vulnerability has been resolved: nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache The shrinker, GC worker, and fsnotify/lease callbacks can unhash an nfsd_file from the rhashtable and then ca...