Junglewise Threat Intelligence

CVE-2026-89665: Linux kernel NFSv2 SETATTR/CREATE out-of-range useconds rejection

CVE-2026-89665 · Severity: high · CVSS 8.2 · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's NFSv2 implementation did not properly validate timestamp microsecond values during file attribute setting and creation operations. An attacker could supply malformed timestamp values that would wrap around and cause incorrect time values to be stored on the filesystem, potentially enabling unauthorized modification of file timestamps or other metadata corruption.

Technical details

The vulnerability exists in the NFSv2 sattr decoder (svcxdr_decode_sattr) where useconds values are converted to nanoseconds via multiplication without prior range validation. On 32-bit systems (ILP32), out-of-range useconds values greater than 1,000,000 wrap during the multiplication by NSEC_PER_USEC (1000), resulting in corrupted nanosecond values that bypass later range checks. The fix adds guards in the decoder to reject useconds values greater than 1,000,000 before multiplication, while preserving the Sun convention value of 1,000,000 which indicates "use current server time". The vulnerability affects both SETATTR and CREATE operations and can be exploited by any NFSv2 client with network access to the NFS server without requiring authentication.

Affected products

  • Linux Linux kernel <UNKNOWN>

Timeline

  • 2026-09-11: disclosed
  • 2026-09-11: patched: Fix applied with decoder guards for useconds validation

Related threats