Description
In the Linux kernel, the following vulnerability has been resolved:

nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget

The XDR buffer size calculation in nfsd4_ff_encode_layoutget() has
multiple errors that can result in either an out-of-bounds write or
leaking uninitialized kernel memory to the client:

- fh_len doesn't account for XDR padding on the file handle data
- uid and gid lengths use "8 + len" but xdr_encode_opaque() actually
writes "4 + xdr_align_size(len)" bytes
- ds_len omits the flags and stats_collect_hint fields (8 bytes),
while len's header constant overestimates by 8 bytes -- these
partially cancel but leave a net mismatch

The worst case occurs with short strings (e.g. uid=0, gid=0 with an
odd-sized file handle), where the function writes up to 5 bytes past
the reserved XDR buffer. Conversely, when string lengths happen to be
4-byte aligned, the reservation is too large and stale buffer content
is sent to the client.

Fix this by breaking out every encoded field explicitly in the ds_len
calculation, using xdr_align_size() for all variable-length opaque
fields, and correcting the header constants.
Published: 2026-09-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Potential Remote Code Execution or Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel’s NFS server contains an error in the XDR length calculation performed by nfsd4_ff_encode_layoutget. The improperly accounting for padding and variable‑length fields results in an out‑of‑bounds write or leakage of uninitialized kernel memory to a client. This creates a buffer‑overflow vulnerability (CWE‑805) that can enable an attacker to obtain remote code execution or elevate privileges if the attacker can craft a malicious layout‑get request.

Affected Systems

Vulnerable kernels are those that have not incorporated commit 0380129b1373c437eb35401a174671c8888f4b80. The issue resides in the generic NFS server component across all Linux kernel versions until the patch is applied. Systems running any distribution whose kernel package lacks this update, regardless of major release, are affected.

Risk and Exploitability

The CVSS score of 9.8 reflects critical severity, while the EPSS score of < 1 % indicates a very low probability of exploitation. It is not listed in the CISA KEV catalog. The likely attack vector is remote over a network, requiring an attacker to send a crafted NFSv4 layout‑get request to the vulnerable server. Based on the description, the exploit would involve inducing an out‑of‑bounds write or leaking kernel data to a client; attackers would need network access to the NFS server.

Generated by OpenCVE AI on September 15, 2026 at 20:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that includes commit 0380129b1373c437eb35401a174671c8888f4b80, which fixes the buffer‑overflow error (CWE‑805), or upgrade to a distribution kernel that implements the fix.
  • If a kernel upgrade is not immediately available, restrict the NFS server to trusted networks, block layout‑get traffic with firewall rules, and thereby mitigate the risk of CWE‑805 exploitation.
  • Monitor vendor advisories and security feeds for evidence of exploitation of the buffer‑overflow flaw (CWE‑805), and consider network segmentation or micro‑segmentation to isolate the NFS service.

Generated by OpenCVE AI on September 15, 2026 at 20:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-787

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-805
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Important


Sat, 12 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-787

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget The XDR buffer size calculation in nfsd4_ff_encode_layoutget() has multiple errors that can result in either an out-of-bounds write or leaking uninitialized kernel memory to the client: - fh_len doesn't account for XDR padding on the file handle data - uid and gid lengths use "8 + len" but xdr_encode_opaque() actually writes "4 + xdr_align_size(len)" bytes - ds_len omits the flags and stats_collect_hint fields (8 bytes), while len's header constant overestimates by 8 bytes -- these partially cancel but leave a net mismatch The worst case occurs with short strings (e.g. uid=0, gid=0 with an odd-sized file handle), where the function writes up to 5 bytes past the reserved XDR buffer. Conversely, when string lengths happen to be 4-byte aligned, the reservation is too large and stale buffer content is sent to the client. Fix this by breaking out every encoded field explicitly in the ds_len calculation, using xdr_align_size() for all variable-length opaque fields, and correcting the header constants.
Title nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:01:59.946Z

Reserved: 2026-09-11T19:38:34.746Z

Link: CVE-2026-89674

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:54.013

Modified: 2026-09-14T13:19:19.450

Link: CVE-2026-89674

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:45:58Z

Links: CVE-2026-89674 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:30:10Z

Weaknesses
  • CWE-805

    Buffer Access with Incorrect Length Value