Description
In the Linux kernel, the following vulnerability has been resolved:

nfsd: validate nseconds in TIME_DELEG decode paths

The xdrgen-based TIME_DELEG_ACCESS and TIME_DELEG_MODIFY decode arms
store a raw uint32_t nseconds directly into tv_nsec without enforcing
nseconds < NSEC_PER_SEC. The legacy nfsd4_decode_nfstime4 has this
check but the TIME_DELEG paths do not. A malformed timespec can
propagate through notify_change() to disk.

Add range checks in both nfs4xdr.c (SETATTR path) and
nfs4callback.c (CB_GETATTR path).
Published: 2026-09-11
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Potential disk corruption or service disruption via malformed NFS timestamps
Action: Patch kernel
AI Analysis

Impact

In the Linux kernel’s NFSv4 server, time fields received in the TIME_DELEG_ACCESS and TIME_DELEG_MODIFY decode paths are copied directly into a timespec structure without checking that the nanoseconds component is less than one billion. A malicious NFS client can therefore send a timestamp with an out‑of‑range nanoseconds value. When this unchecked value propagates through a notify_change() call to the underlying filesystem, it can corrupt disk metadata, potentially leading to data loss or a crash of the NFS service. The weakness represents an input‑validation failure that compromises data integrity.

Affected Systems

All Linux kernels that provide the NFSv4 server and have not incorporated the upstream commit adding the range checks are affected. This includes every distribution running a kernel before the described fix, because the flaw resides in the core nfs4xdr and nfs4callback modules.

Risk and Exploitability

The CVSS score of 6.8 indicates a moderate severity and that an attacker with network access to the NFSv4 daemon could score of <1% suggests that exploitation is currently unlikely, and the vulnerability is not listed in CISA KEV. Nonetheless, the possibility of disk metadata corruption or service disruption makes the risk significant for hosts that accept untrusted NFS traffic.

Generated by OpenCVE AI on September 15, 2026 at 19:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the commit adding range checks to TIME_DELEG paths.
  • Restrict NFSv4 server exposure by firewalling or limiting client IPs to trusted networks.
  • Enable filesystem integrity monitoring or checksum verification to detect any potential corruption that may have occurred before the vulnerability was patched.

Generated by OpenCVE AI on September 15, 2026 at 19:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1284
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nfsd: validate nseconds in TIME_DELEG decode paths The xdrgen-based TIME_DELEG_ACCESS and TIME_DELEG_MODIFY decode arms store a raw uint32_t nseconds directly into tv_nsec without enforcing nseconds < NSEC_PER_SEC. The legacy nfsd4_decode_nfstime4 has this check but the TIME_DELEG paths do not. A malformed timespec can propagate through notify_change() to disk. Add range checks in both nfs4xdr.c (SETATTR path) and nfs4callback.c (CB_GETATTR path).
Title nfsd: validate nseconds in TIME_DELEG decode paths
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:46:18.807Z

Reserved: 2026-09-11T19:38:34.750Z

Link: CVE-2026-89701

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:57.303

Modified: 2026-09-11T20:19:57.303

Link: CVE-2026-89701

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:18Z

Links: CVE-2026-89701 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:00:08Z

Weaknesses
  • CWE-1284

    Improper Validation of Specified Quantity in Input