Description
In the Linux kernel, the following vulnerability has been resolved:

NFSD: check truncate permission under inode lock

nfsd_setattr() checks whether a size update needs NFSD_MAY_TRUNC
before it takes inode_lock(). The comparison uses the file size sampled
by that unlocked read, but the actual ATTR_SIZE update is applied later
under inode_lock() by notify_change().

This leaves a TOCTOU window for append-only files. If a client sends a
SETATTR that does not shrink the file at the time of the unlocked
sample, a concurrent append can extend the file before nfsd_setattr()
takes inode_lock(). notify_change() then applies a real truncation
without the NFSD_MAY_TRUNC check that rejects IS_APPEND(inode). The VFS
truncate syscall paths perform their own append-only checks before
calling notify_change(), so NFSD must make this decision against the
locked size it is about to change.

Split the write-count acquisition from the truncation permission check.
Keep get_write_access() before the locked setattr work, then recheck
whether the requested size is below i_size_read(inode) after inode_lock()
has been acquired and before notify_change(ATTR_SIZE). This also avoids
the plain unlocked inode->i_size load.
Published: 2026-09-11
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Truncation of append‑only files via a TOCTOU race in the NFS server
Action: Patch kernel
AI Analysis

Impact

The vulnerability lies in the Linux kernel’s NFSD_MAY_TRUNC) is performed before the inode lock is taken. This creates a time‑of‑check to time‑of‑use window that can be exploited to truncate a file that is marked append‑only. Based on the description, it is inferred that an attacker could trigger this race by sending a SETATTR request that does not shrink the file and then timing an append operation such that the file size grows before the inode lock is acquired. The result is data loss or corruption of the append‑only file.

Affected Systems

All Linux kernel builds that have not incorporated the NFS server patch are affected, regardless of distribution. The flaw is located in core kernel code that handles NFS set‑attribute requests, so any deployment running an unpatched NFS daemon is at risk. No specific version range is given, implying that the issue exists in every kernel release that lacks the fix.

Risk and Exploitability

The CVSS score of 9.1 indicates high severity, while the EPSS score of less than 1% suggests a low probability The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an NFS client with write access that can issue a SETATTR request while another process performs an append, exploiting the race. Because the window of opportunity is narrow and the attacker requires privileged write access on the NFS server, the overall risk is high impact but low likelihood in environments where the condition is satisfied.

Generated by OpenCVE AI on September 15, 2026 at 19:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that includes the NFS server patch.
  • If the patch cannot be deployed immediately, remount affected NFS shares read‑only or remove write permissions for append‑only files using ACLs.
  • hosts and monitor SETATTR traffic for abnormal patterns.

Generated by OpenCVE AI on September 15, 2026 at 19:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}


Sat, 12 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H'}

threat_severity

Moderate


Sat, 12 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
CWE-367

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: NFSD: check truncate permission under inode lock nfsd_setattr() checks whether a size update needs NFSD_MAY_TRUNC before it takes inode_lock(). The comparison uses the file size sampled by that unlocked read, but the actual ATTR_SIZE update is applied later under inode_lock() by notify_change(). This leaves a TOCTOU window for append-only files. If a client sends a SETATTR that does not shrink the file at the time of the unlocked sample, a concurrent append can extend the file before nfsd_setattr() takes inode_lock(). notify_change() then applies a real truncation without the NFSD_MAY_TRUNC check that rejects IS_APPEND(inode). The VFS truncate syscall paths perform their own append-only checks before calling notify_change(), so NFSD must make this decision against the locked size it is about to change. Split the write-count acquisition from the truncation permission check. Keep get_write_access() before the locked setattr work, then recheck whether the requested size is below i_size_read(inode) after inode_lock() has been acquired and before notify_change(ATTR_SIZE). This also avoids the plain unlocked inode->i_size load.
Title NFSD: check truncate permission under inode lock
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:33:36.076Z

Reserved: 2026-09-11T19:38:34.751Z

Link: CVE-2026-89713

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:58.743

Modified: 2026-09-13T07:17:37.013

Link: CVE-2026-89713

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:27Z

Links: CVE-2026-89713 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:30:12Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition