Description
In the Linux kernel, the following vulnerability has been resolved:

nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr()

The BOTH_TIME_SET branch calls fh_verify() early so setattr_prepare()
can inspect the dentry. This causes nfsd_setattr() to skip
fh_want_write(), so notify_change() runs without a mount write
reference.

Add the missing fh_want_write() call after the early fh_verify().
Published: 2026-09-11
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via Unauthorized Attribute Modification
Action: Apply Patch
AI Analysis

Impact

In the Linux kernel NFS server, the flaw is introduced when fh_verify() is called early in the setattr path, causing the subsequent fh_want_write() check to be skipped. This omission means that notify_change() can execute without, an NFS client can issue a SETATTR request that modifies file permissions, ownership, or timestamps on exported files without needing the usual write permissions. This ability permits unauthorized attribute modification and can lead to privilege escalation or data tampering.

Affected Systems

The vulnerability impacts the Linux kernel's NFS kernel itself. No specific kernel version is enumerated in the data, implying that any kernel release lacking the fh_want_write() addition is potentially vulnerable. Until the patch is incorporated, all unpatched kernel builds that implement the NFS server should be considered at risk.

Risk and Exploitability

The CVSS score of 9.1 signals high severity, yet the EPSS score of < 1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker can exploit the flaw remotely by sending a malicious SETATTR RPC to a vulnerable NFS server. The attack requires network connectivity and sufficient access to the exported file system; local exploitation would need equivalent privileges. No additional constraints or software dependencies are noted, implying a standard NFS client is sufficient to perform the attack.

Generated by OpenCVE AI on September 15, 2026 at 19:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the fh_want_write() addition in the NFS setattr path.
  • If a kernel update cannot be applied immediately, restrict SETATTR privileges by adjusting NFS export options or applying mandatory access controls to limit which users or processes can modify file attributes on the server.
  • Configure audit rules to log NFS SETATTR requests and review logs for suspicious activity.

Generated by OpenCVE AI on September 15, 2026 at 19:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-911
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr() The BOTH_TIME_SET branch calls fh_verify() early so setattr_prepare() can inspect the dentry. This causes nfsd_setattr() to skip fh_want_write(), so notify_change() runs without a mount write reference. Add the missing fh_want_write() call after the early fh_verify().
Title nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:02:04.273Z

Reserved: 2026-09-11T19:38:34.750Z

Link: CVE-2026-89697

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:56.843

Modified: 2026-09-14T13:19:20.060

Link: CVE-2026-89697

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:46:15Z

Links: CVE-2026-89697 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:00:08Z

Weaknesses
  • CWE-911

    Improper Update of Reference Count