Description
In the Linux kernel, the following vulnerability has been resolved:

nfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage

struct nfsd_genl_rqstp declares rq_daddr and rq_saddr as plain
"struct sockaddr" (16 bytes). When an IPv6 NFS client is connected,
nfsd_genl_rpc_status_compose_msg() casts these fields to
"struct sockaddr_in6 *" (28 bytes) and reads sin6_addr at offset 8..24,
which extends 8 bytes past the end of the 16-byte sockaddr field into
the adjacent rq_flags member. The 16-byte nla_put_in6_addr then ships 8
bytes of truncated IPv6 address followed by 8 bytes of rq_flags to
userspace via the NFSD_A_RPC_STATUS_SADDR6/DADDR6 netlink attributes.

This is reachable by any unprivileged process in the network namespace
because NFSD_CMD_RPC_STATUS_GET uses GENL_CMD_CAP_DUMP without
GENL_ADMIN_PERM.

Fix by widening rq_daddr and rq_saddr to struct sockaddr_storage so the
IPv6 casts operate within bounds, copying sizeof(struct sockaddr_storage)
bytes in the memcpy calls so the full address is captured, and
zero-initializing the genl_rqstp stack variable to prevent leaking
uninitialized tail bytes through netlink.
Published: 2026-09-11
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

A buffer over‑read in the Linux kernel's NFS read past the bounds of a struct sockaddr field and leak unmember. The over‑read can expose memory contents to userspace via NFSD_A_RPC_STATUS_SADDR6/DADDR6 netlink attributes, potentially revealing sensitive data. The flaw arises when an IPv6 client is serviced, causing the code to cast to a larger struct sockaddr_in6 and read beyond its allocated space. This weakness falls under CWE‑125 – Buffer Over‑read.

Affected Systems

The vulnerability is present in the Linux kernel on all versions before the removal of the prototype that declares rq_daddr and rq_saddr as plain struct sockaddr. Exact version ranges are not provided, but all builds that have not applied the patch commit that widens these fields to struct sockaddr_storage are affected.

Risk and Exploitability

The CVSS base score is 6.5, indicating a medium severity that can be leveraged by any unprivileged process running in the same network namespace. The EPSS score is < 1%, and the entry is not listed in the CISA KEV catalog, suggesting no widespread exploitation detected yet. Because the attack path requires no special privileges and relies on standard NFS netlink commands, the risk to untrusted users.

Generated by OpenCVE AI on September 15, 2026 at 19:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that widens nfsd_genl_rqstp address fields to sockaddr_storage (commit c03c512f22d3fbe7a3767d6df5e3d88b8e7c105e5).
  • If possible, configure the kernel to to unprivileged users or disable NFSD_CMD_RPC_STATUS_GET in the NFS configuration.
  • Verify that the kernel does not expose the genl_rqstp stack variable and monitor netlink traffic for unexpected RPC_STATUS_GET requests.

Generated by OpenCVE AI on September 15, 2026 at 19:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 21 Sep 2026 13:30:00 +0000


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage struct nfsd_genl_rqstp declares rq_daddr and rq_saddr as plain "struct sockaddr" (16 bytes). When an IPv6 NFS client is connected, nfsd_genl_rpc_status_compose_msg() casts these fields to "struct sockaddr_in6 *" (28 bytes) and reads sin6_addr at offset 8..24, which extends 8 bytes past the end of the 16-byte sockaddr field into the adjacent rq_flags member. The 16-byte nla_put_in6_addr then ships 8 bytes of truncated IPv6 address followed by 8 bytes of rq_flags to userspace via the NFSD_A_RPC_STATUS_SADDR6/DADDR6 netlink attributes. This is reachable by any unprivileged process in the network namespace because NFSD_CMD_RPC_STATUS_GET uses GENL_CMD_CAP_DUMP without GENL_ADMIN_PERM. Fix by widening rq_daddr and rq_saddr to struct sockaddr_storage so the IPv6 casts operate within bounds, copying sizeof(struct sockaddr_storage) bytes in the memcpy calls so the full address is captured, and zero-initializing the genl_rqstp stack variable to prevent leaking uninitialized tail bytes through netlink.
Title nfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-21T13:14:49.619Z

Reserved: 2026-09-11T19:38:34.750Z

Link: CVE-2026-89698

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:56.957

Modified: 2026-09-21T14:17:25.457

Link: CVE-2026-89698

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:46:16Z

Links: CVE-2026-89698 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:00:08Z

Weaknesses