Description
In the Linux kernel, the following vulnerability has been resolved:

nfsd: fix null dereference in nfsd4_setattr for deleg timestamp attrs

When a SETATTR request includes FATTR4_WORD2_TIME_DELEG_ACCESS or
FATTR4_WORD2_TIME_DELEG_MODIFY in the attribute bitmap, nfsd4_setattr()
sets deleg_attrs=true and calls nfs4_preprocess_stateid_op() to validate
the stateid.

If the client supplies the NFSv4 "one stateid" (all-0xFF bytes),
check_special_stateids() returns nfs_ok without populating the output
nfs4_stid pointer, because the special-stateid path in
nfs4_preprocess_stateid_op() jumps to done: with s==NULL, and the
"if (s)" block that would set *cstid is skipped. The local variable `st`
remains NULL.

Back in nfsd4_setattr(), the if (deleg_attrs) block then unconditionally
dereferences st->sc_type (at offset 4 from NULL), causing a kernel oops.

This is remotely triggerable by any NFSv4 client: send COMPOUND [PUTROOTFH,
SETATTR(ONE_STATEID, {bmval2=FATTR4_WORD2_TIME_DELEG_ACCESS, ...})].
No authentication, delegation, or prior state is required.

Fix by adding a NULL check before the dereference. A special stateid is
not a delegation stateid, so the existing nfserr_bad_stateid return value
is already correct; we only need to guard the pointer dereference itself.
Published: 2026-09-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Denial of Service via NFSv4 SETATTR Null Dereference
Action: Immediate Patch
AI Analysis

Impact

A null pointer dereference flaw exists in the Linux kernel’s NFSv4 server code. When a SETATTR request includes delegation timestamp attributes and the client supplies an all‑0xFF stateid, the kernel fails to check for a NULL pointer before accessing it, causing a kernel oops that crashes the system and leads to denial of service. The flaw is classified as CWE‑476 and carries a CVSS score of 7.5, reflecting a high severity impact on availability with no direct effect on confidentiality. Operators should verify their kernel version against the patch that introduces the null‑check guard.

Affected Systems

The vulnerability impacts the Linux kernel’s NFSv4 server component across all Linux distributions that ship this module. Systems running kernel versions that do not include the patch adding the null‑check in nfsd4_setattr are vulnerable. The fix appears in the commits c5119b799a7f57..., c896db123892256..., fe456c8c0931bb3e8a03d429920e87fd85747fba. No specific distribution or version range was enumerated in the CVE, so any publicly available kernel without this patch remains at risk.

Risk and Exploitability

The flaw can be triggered remotely by any NFSv4 client through a COMPOUND transaction that includes the delegation timestamp attributes with the all‑0xFF stateid, requiring no special authentication or privileged state. The EPSS score of <1% indicates a very low exploitation probability today, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread active exploitation. Nevertheless, the CVSS score of 7.5 and the trivial remote trigger path warrant prompt attention, especially for systems exposing NFSv4 to untrusted networks.

Generated by OpenCVE AI on September 15, 2026 at 20:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel update that includes the null‑check modification to nfsd4_setattr, referencing the advisory commits.
  • If an immediate kernel upgrade is not feasible, restrict the NFSv4 export to trusted hosts or block SETATTR operations from unknown clients via firewall rules.
  • Continuously monitor kernel audit NFSv4 logs for abnormal SETATTR requests that may indicate probing or exploitation attempts.

Generated by OpenCVE AI on September 15, 2026 at 20:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nfsd: fix null dereference in nfsd4_setattr for deleg timestamp attrs When a SETATTR request includes FATTR4_WORD2_TIME_DELEG_ACCESS or FATTR4_WORD2_TIME_DELEG_MODIFY in the attribute bitmap, nfsd4_setattr() sets deleg_attrs=true and calls nfs4_preprocess_stateid_op() to validate the stateid. If the client supplies the NFSv4 "one stateid" (all-0xFF bytes), check_special_stateids() returns nfs_ok without populating the output nfs4_stid pointer, because the special-stateid path in nfs4_preprocess_stateid_op() jumps to done: with s==NULL, and the "if (s)" block that would set *cstid is skipped. The local variable `st` remains NULL. Back in nfsd4_setattr(), the if (deleg_attrs) block then unconditionally dereferences st->sc_type (at offset 4 from NULL), causing a kernel oops. This is remotely triggerable by any NFSv4 client: send COMPOUND [PUTROOTFH, SETATTR(ONE_STATEID, {bmval2=FATTR4_WORD2_TIME_DELEG_ACCESS, ...})]. No authentication, delegation, or prior state is required. Fix by adding a NULL check before the dereference. A special stateid is not a delegation stateid, so the existing nfserr_bad_stateid return value is already correct; we only need to guard the pointer dereference itself.
Title nfsd: fix null dereference in nfsd4_setattr for deleg timestamp attrs
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:33:02.395Z

Reserved: 2026-09-11T19:38:34.747Z

Link: CVE-2026-89679

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:54.660

Modified: 2026-09-13T07:17:33.647

Link: CVE-2026-89679

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:46:02Z

Links: CVE-2026-89679 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:30:10Z

Weaknesses