Description
In the Linux kernel, the following vulnerability has been resolved:

nfsd: fix partial-write detection in nfsd_direct_write

nfsd_direct_write() walks a list of write segments and, after each
vfs_iocb_iter_write(), tries to detect a short write so the loop can
stop before placing the next segment at a wrong file offset:

host_err = vfs_iocb_iter_write(file, kiocb, &segments[i].iter);
if (host_err < 0)
return host_err;
*cnt += host_err;
if (host_err < segments[i].iter.count)
break; /* partial write */

vfs_iocb_iter_write() runs the iter through ->write_iter(), which
advances the iter by the number of bytes written. By the time the
check runs, segments[i].iter.count is the residual, not the original
request length:

before write_iter: iter.count == original_len
after write_iter: iter.count == original_len - host_err

The condition then reduces to host_err < original_len - host_err, so
the break fires only when less than half of the segment was written.
Any short write completing between 50% and 99% of the segment slips
through; the loop advances to the next segment with kiocb->ki_pos
only bumped by the short amount, writing the next segment's payload
at the wrong offset and over-reporting *cnt to the NFS client.

Snapshot the segment's byte count before the write and compare
host_err against that snapshot so any short write breaks the loop.
Published: 2026-09-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: File integrity compromise due to incorrect handling of partial NFS writes
Action: Patch Immediately
AI Analysis

Impact

The Linux kernel NFS daemon contains a logic error in nfsd_direct_write where the loop that processes NFS write segments fails to properly detect partial writes that complete between 50% and 99%. The loop compares the bytes written against a residual count that has already been reduced, causing the condition to trigger only when less than half of the segment is written. As a result, subsequent segments are written at a file offset that is off by the short write amount, overwriting or corrupting data. The vulnerability manifests only when a malicious NFS client issues specially crafted write requests that advance the offset incorrectly. Based on the description, it is inferred that an attacker needs the ability to send NFS write requests to the server and must have write access to a file exposed via NFS, but no higher privileges.

Affected Systems

All Linux kernels that contain the unpatched nfsd_direct_write path are vulnerable, regardless of distribution. The advisory does not enumerate specific kernel releases, so any kernel snapshot prior to the commit appears in the Linux kernel repository should be considered at risk. This includes stock kernels shipped in many popular Linux distributions as well as custom kernels that have not been updated.

Risk and Exploitability

The CVSS score of 7.5 reflects high severity, whereas the EPSS score of less than 1% indicates a low probability of widespread exploitation at this time. The vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector involves remote NFS write access, because the bug manifests when an NFS client sends write traffic that triggers the logic error. Inference from the description suggests that the attacker would need to have write access to an NFS‑exported file, but no other privileged context beyond NFS write access. If the logic error is triggered, file contents can be corrupted or overwritten, potentially leading to data loss or integrity violations.

Generated by OpenCVE AI on September 15, 2026 at 20:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Linux kernel patch (commit 250ec14932d5cfe102f68a57892bb566eee7f83e) to fix the logic error tied to CWE‑823.
  • Restrict NFS traffic to trusted hosts or implement firewall rules limiting NFS write access, thereby reducing exposure to the CWE‑823 condition.
  • If an immediate kernel update is not possible, temporarily unmount NFS shares that may be used by untrusted clients until the patch can be applied.
  • Deploy file‑integrity monitoring for NFS‑exported files to detect unexpected changes caused by the CWE‑823 issue.

Generated by OpenCVE AI on September 15, 2026 at 20:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-823
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nfsd: fix partial-write detection in nfsd_direct_write nfsd_direct_write() walks a list of write segments and, after each vfs_iocb_iter_write(), tries to detect a short write so the loop can stop before placing the next segment at a wrong file offset: host_err = vfs_iocb_iter_write(file, kiocb, &segments[i].iter); if (host_err < 0) return host_err; *cnt += host_err; if (host_err < segments[i].iter.count) break; /* partial write */ vfs_iocb_iter_write() runs the iter through ->write_iter(), which advances the iter by the number of bytes written. By the time the check runs, segments[i].iter.count is the residual, not the original request length: before write_iter: iter.count == original_len after write_iter: iter.count == original_len - host_err The condition then reduces to host_err < original_len - host_err, so the break fires only when less than half of the segment was written. Any short write completing between 50% and 99% of the segment slips through; the loop advances to the next segment with kiocb->ki_pos only bumped by the short amount, writing the next segment's payload at the wrong offset and over-reporting *cnt to the NFS client. Snapshot the segment's byte count before the write and compare host_err against that snapshot so any short write breaks the loop.
Title nfsd: fix partial-write detection in nfsd_direct_write
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:33:01.153Z

Reserved: 2026-09-11T19:38:34.747Z

Link: CVE-2026-89678

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:54.523

Modified: 2026-09-13T07:17:33.533

Link: CVE-2026-89678

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:46:02Z

Links: CVE-2026-89678 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:30:10Z

Weaknesses
  • CWE-823

    Use of Out-of-range Pointer Offset