Junglewise Threat Intelligence

CVE-2026-89666: Linux kernel NFSv3 out-of-range timestamp validation

CVE-2026-89666 · Severity: info · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's NFSv3 server (nfsd) did not validate that client-supplied timestamps in file operations have valid nanosecond values. An attacker sending specially crafted NFSv3 requests could cause on-disk filesystem metadata corruption, affecting file timestamps and potentially corrupting stored dates on ext4 and XFS filesystems.

Technical details

The vulnerability exists in NFSv3 SETATTR, CREATE, MKDIR, SYMLINK, and MKNOD operations. A client can send a valid wire-format time value with a nanoseconds (tv_nsec) field exceeding NSEC_PER_SEC (1,000,000,000), which violates the timespec64 contract. The nfsd server did not validate this constraint; notify_change() and timestamp_truncate() pass the invalid value through unchanged when filesystem nanosecond granularity is enabled. Filesystems like ext4 (via ext4_encode_extra_time()) and XFS (with bigtime) then mishandle the oversized value during encoding, corrupting the seconds-epoch bits and causing stored timestamps to reference incorrect years. The fix adds validation in NFSv3 proc handlers to reject out-of-range tv_nsec values with NFS3ERR_INVAL before any filesystem changes occur.

Affected products

  • Linux Linux kernel <parameter>

Timeline

  • 2026-09-11: disclosed: CVE-2026-89666 published

Related threats