Description
In the Linux kernel, the following vulnerability has been resolved:

nfsd: validate symlink target length in NFSv4 CREATE

nfsd4_decode_create() accepts an unbounded cr_datalen from the wire for
NF4LNK symlink targets, allowing a client to force a kmalloc of up to
the maximum RPC payload size (several MiB) per COMPOUND op that persists
until compound teardown. The VFS rejects oversized targets with
ENAMETOOLONG, but the allocation has already occurred.

Reject cr_datalen == 0 early with nfserr_inval and cr_datalen greater
than NFS4_MAXPATHLEN (PATH_MAX) with nfserr_nametoolong to bound the
allocation.
Published: 2026-09-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via kernel memory exhaustion
Action: Apply patch
AI Analysis

Impact

The Linux NFS daemon suffers from an unbounded allocation of symlink target When a client sends a symlink creation request containing path size, the kernel’s nfsd4 target before validating its size, enabling a malicious client to force a kmalloc that can consume several megabytes of kernel memory. This memory can persist until the NFS compound operation completes, potentially exhausting kernel memory and leading to a server crash or CWE-770, indicating resource exhaustion.

Affected Systems

The vulnerability applies to all builds of the Linux kernel that do not include the patch that adds an upper bound check on symlink target lengths. No specific kernel version range is enumerated, so any compile‑time Linux kernel before the commit that implements the check is potentially vulnerable. Systems running an NFSv4 server and exposing the service to untrusted clients should verify whether the affected code path is present in their kernel version.

Risk and Exploitability

The CVSS score of 7.5 and EPSS score of less than 1% indicate a low likelihood of exploitation at present. This vulnerability is not listed in the CISA KEV catalog. The flaw can likely be exploited remotely by sending a specially crafted NFS connectivity to the NFS server. The exploit affects kernel space and can lead to a denial of service against the entire server.

Generated by OpenCVE AI on September 15, 2026 at 19:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the symlink target length bound check that was introduced in the referenced commits.
  • If an immediate kernel upgrade is not possible, restrict NFSv4 traffic to trusted networks or block it entirely with firewall rules to prevent malicious CREATE requests.
  • Enable or increase kernel NFS debugging and logging to alert on unusually large symlink target lengths and monitor for potential abuse attempts.

Generated by OpenCVE AI on September 15, 2026 at 19:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nfsd: validate symlink target length in NFSv4 CREATE nfsd4_decode_create() accepts an unbounded cr_datalen from the wire for NF4LNK symlink targets, allowing a client to force a kmalloc of up to the maximum RPC payload size (several MiB) per COMPOUND op that persists until compound teardown. The VFS rejects oversized targets with ENAMETOOLONG, but the allocation has already occurred. Reject cr_datalen == 0 early with nfserr_inval and cr_datalen greater than NFS4_MAXPATHLEN (PATH_MAX) with nfserr_nametoolong to bound the allocation.
Title nfsd: validate symlink target length in NFSv4 CREATE
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:02:05.331Z

Reserved: 2026-09-11T19:38:34.750Z

Link: CVE-2026-89699

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:57.077

Modified: 2026-09-14T13:19:20.213

Link: CVE-2026-89699

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:17Z

Links: CVE-2026-89699 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:00:08Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling