Description
In the Linux kernel, the following vulnerability has been resolved:

nfsd: validate sockaddr length per family in listener_set

nfsd_sock_nl_policy declares NFSD_A_SOCK_ADDR as a bare NLA_BINARY
attribute with no minimum length. A CAP_NET_ADMIN caller can send a
16-byte NFSD_A_SOCK_ADDR with sa_family=AF_INET6, causing a 12-byte
OOB read across three consumers (rpc_cmp_addr_port, svc_find_listener,
kernel_bind).

nfsd_nl_listener_set_doit() also parsed and validated each listener
entry inline in two separate loops, interleaved with mutating the
running listener configuration. The validation was duplicated, used an
open-coded "nla_len < sizeof(struct sockaddr)" check that was too short
for AF_INET6, and handled a malformed entry inconsistently depending on
which loop noticed it.

Add an nfsd_nl_validate_listeners() helper that walks the entire list
once and confirms each entry parses, carries both an address and a
transport name, and is long enough for its address family
(sizeof(struct sockaddr_in) for AF_INET, sizeof(struct sockaddr_in6)
for AF_INET6, -EAFNOSUPPORT otherwise). Call it before taking
nfsd_mutex or creating the serv, so a malformed request fails cleanly
with no side effects.

Since every entry is known valid by the time the two existing loops
run, drop the redundant presence and per-family length checks from
both, leaving only the nla_parse_nested() call needed to extract the
data.
Published: 2026-09-11
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an out‑of‑bounds read in the Linux kernel’s NFS server implementation. A user with CAP_NET_ADMIN can send a malformed NFSD_A_SOCK_ADDR containing a 16‑byte AF_INET6 structure that is too short for the kernel logic, causing three parsing functions to read 12 bytes beyond the buffer. This read exposes arbitrary kernel memory data, which an attacker could use to assist further exploitation. The flaw is a classic CWE‑125 out‑of‑bounds read.

Affected Systems

The affected systems are all Linux kernel installations before the patch that added proper sockaddr length validation in the NFS listener configuration. The advisory does not list specific kernel release numbers, so any host running a pre‑patch kernel is potentially vulnerable. Only the NFS server component contains the vulnerable code path, so only machines that run the NFS server and have CAP_NET_ADMIN privileges are at risk.

Risk and Exploitability

The CVSS score of 4.7 indicates moderate severity. The EPSS score of less than 1% shows the exploitation probability is very low at the time of assessment. The vulnerability requires local privilege (CAP_NET_ADMIN) and is not remotely exploitable, and it is not registered in the CISA KEV catalog. If exploited successfully, the out‑of‑bounds read could reveal kernel memory contents but does not directly lead to code execution; the attacker would still need additional steps to leverage the disclosed information for further compromise.

Generated by OpenCVE AI on September 15, 2026 at 19:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the nfsd sockaddr length validation fix.
  • Restrict CAP_NET_ADMIN privileges to trusted administrators to reduce the attack surface.
  • Disable the NFS server or block listener‑configuration changes if NFS is not required on the host.
  • Enable auditing of NFS listener configuration changes and review kernel logs for suspicious activity.

Generated by OpenCVE AI on September 15, 2026 at 19:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 21 Sep 2026 13:30:00 +0000


Sat, 12 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H'}

threat_severity

Important


Sat, 12 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nfsd: validate sockaddr length per family in listener_set nfsd_sock_nl_policy declares NFSD_A_SOCK_ADDR as a bare NLA_BINARY attribute with no minimum length. A CAP_NET_ADMIN caller can send a 16-byte NFSD_A_SOCK_ADDR with sa_family=AF_INET6, causing a 12-byte OOB read across three consumers (rpc_cmp_addr_port, svc_find_listener, kernel_bind). nfsd_nl_listener_set_doit() also parsed and validated each listener entry inline in two separate loops, interleaved with mutating the running listener configuration. The validation was duplicated, used an open-coded "nla_len < sizeof(struct sockaddr)" check that was too short for AF_INET6, and handled a malformed entry inconsistently depending on which loop noticed it. Add an nfsd_nl_validate_listeners() helper that walks the entire list once and confirms each entry parses, carries both an address and a transport name, and is long enough for its address family (sizeof(struct sockaddr_in) for AF_INET, sizeof(struct sockaddr_in6) for AF_INET6, -EAFNOSUPPORT otherwise). Call it before taking nfsd_mutex or creating the serv, so a malformed request fails cleanly with no side effects. Since every entry is known valid by the time the two existing loops run, drop the redundant presence and per-family length checks from both, leaving only the nla_parse_nested() call needed to extract the data.
Title nfsd: validate sockaddr length per family in listener_set
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-21T13:14:50.652Z

Reserved: 2026-09-11T19:38:34.750Z

Link: CVE-2026-89700

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:57.187

Modified: 2026-09-21T14:17:25.580

Link: CVE-2026-89700

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:46:18Z

Links: CVE-2026-89700 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:00:08Z

Weaknesses