Description
In the Linux kernel, the following vulnerability has been resolved:

nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo

nfsd4_ff_encode_getdeviceinfo() computes the da_addr_body reservation
as 16 + netid_len + addr_len, but the subsequent xdr_encode_opaque()
calls emit 8 + round_up(netid_len, 4) + round_up(addr_len, 4) bytes.
The mismatch means the declared da_addr_body length exceeds the actual
encoded data by 2-8 bytes on every flexfile GETDEVICEINFO reply,
leaking stale reply-page content to the client and mis-aligning the
subsequent version list decode.

Use xdr_align_size() for each string length to match what
xdr_encode_opaque() actually writes.
Published: 2026-09-11
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch Immediately
AI Analysis

Impact

A flaw in the NFS server’s handling of the GETDEVICEINFO RPC causes the response payload size to be incorrectly calculated. The server declares does, and this discrepancy results in the client receiving stale contents from previous replies. The data leak occurs for every GETDEVICEINFO reply, potentially exposing residual data from prior operations and causing downstream corruption when subsequent fields are decoded.

Affected Systems

All Linux kernel builds that compile with the NFS server (nfsd) and expose the GETDEVICEINFO operation are vulnerable. Kernel versions that lack the fix for the XDR padding mismatch must be considered exposed until patched.

Risk and Exploitability

The CVSS score of 5.9 categorises the issue as moderate. The EPSS score of less than 1 % indicates that exploitation is unlikely, and the vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is a remote NFS client that sends a crafted GETDEVICEINFO request over the network to the vulnerable server, causing the malformed response to be produced and the client to receive leaked data.

Generated by OpenCVE AI on September 15, 2026 at 20:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the patch for CVE-2026-89673
  • Reconfigure the NFS server to disable or restrict the GETDEVICEINFO operation so that the vulnerable code path is not exercised
  • Restrict NFS traffic to trusted hosts only, enforce firewall rules to limit access, and monitor for anomalous GETDEVICEINFO traffic

Generated by OpenCVE AI on September 15, 2026 at 20:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 12:30:00 +0000


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo nfsd4_ff_encode_getdeviceinfo() computes the da_addr_body reservation as 16 + netid_len + addr_len, but the subsequent xdr_encode_opaque() calls emit 8 + round_up(netid_len, 4) + round_up(addr_len, 4) bytes. The mismatch means the declared da_addr_body length exceeds the actual encoded data by 2-8 bytes on every flexfile GETDEVICEINFO reply, leaking stale reply-page content to the client and mis-aligning the subsequent version list decode. Use xdr_align_size() for each string length to match what xdr_encode_opaque() actually writes.
Title nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:01:58.863Z

Reserved: 2026-09-11T19:38:34.746Z

Link: CVE-2026-89673

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:53.890

Modified: 2026-09-14T13:19:19.333

Link: CVE-2026-89673

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:45:58Z

Links: CVE-2026-89673 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:30:10Z

Weaknesses