Description
A stack buffer overflow vulnerability was found in the 9P protocol implementation of NFS-Ganesha. The server does not validate the number of path components in a TWALK request against the protocol-defined limit of 16. An attacker can send a specially crafted TWALK message with thousands of path components, causing the server to write past the end of a fixed-size stack buffer during response construction. This can result in a crash or potentially remote code execution. The 9P protocol handler does not implement authentication, so the vulnerability is reachable without credentials by any client with network access to the 9P listener.
Published: n/a
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A stack buffer overflow occurs in the 9P protocol implementation of NFS-Ganesha when the server fails to enforce the maximum number of path components defined by the 9P protocol. A specially crafted TWALK request containing thousands of path components overwrites a fixed-size stack buffer during response construction. This can cause a crash or, depending on the environment, remote code execution. The flaw is a classic stack-based buffer overflow (CWE-121).

Affected Systems

Any NFS-Ganesha server that exposes the 9P protocol listener is affected. No specific version information was provided, so all deployments are potentially vulnerable until patched.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Because authentication is not enforced on the 9P listener, any network client can send the malicious TWALK request, making the attack vector local network or over the Internet if the listener is exposed. The exploit requires only a crafted message; no privileged access or persistence is needed to trigger the overflow.

Generated by OpenCVE AI on October 6, 2026 at 13:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest NFS-Ganesha patch that fixes the 9P TWALK component count validation bug
  • Restrict network access to the 9P listener using firewall rules or network segmentation to limit exposure to trusted hosts
  • Monitor server logs for abnormal TWALK requests and other 9P protocol anomalies to detect potential exploitation attempts

Generated by OpenCVE AI on October 6, 2026 at 13:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 12:15:00 +0000

Type Values Removed Values Added
Description A stack buffer overflow vulnerability was found in the 9P protocol implementation of NFS-Ganesha. The server does not validate the number of path components in a TWALK request against the protocol-defined limit of 16. An attacker can send a specially crafted TWALK message with thousands of path components, causing the server to write past the end of a fixed-size stack buffer during response construction. This can result in a crash or potentially remote code execution. The 9P protocol handler does not implement authentication, so the vulnerability is reachable without credentials by any client with network access to the 9P listener.
Title nfs-ganesha: nfs-ganesha: 9P TWALK component count stack buffer overflow
Weaknesses CWE-121
References
Metrics threat_severity

None

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Critical


Subscriptions

No data.

cve-icon MITRE

No data.

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Critical

Publid Date: 2026-10-05T00:00:00Z

Links: CVE-2026-105516 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T13:45:18Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow