Junglewise Threat Intelligence

CVE-2026-89679: Linux kernel null dereference in nfsd4_setattr delegation handling

CVE-2026-89679 · Severity: high · CVSS 7.5 · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's NFSv4 server implementation (nfsd) contains a null pointer dereference in the SETATTR request handler when a client specifies delegation timestamp attributes. A remote attacker can send a specially crafted NFSv4 request to cause a kernel panic and denial of service, with no authentication or prior state required.

Technical details

The vulnerability exists in the nfsd4_setattr() function in fs/nfsd/nfs4proc.c. When processing a SETATTR request containing FATTR4_WORD2_TIME_DELEG_ACCESS or FATTR4_WORD2_TIME_DELEG_MODIFY attributes, the function calls nfs4_preprocess_stateid_op() to validate the stateid. However, if the client supplies the NFSv4 "one stateid" (all 0xFF bytes), the check_special_stateids() function returns success without populating the output nfs4_stid pointer, leaving the local variable 'st' as NULL. The code then unconditionally dereferences st->sc_type without checking for NULL, causing a kernel oops at offset 4 from NULL. This is remotely triggerable by any NFSv4 client without authentication or prior state. The fix adds a NULL check (if (st && (st->sc_type & SC_TYPE_DELEG))) before the dereference.

Affected products

  • Linux Linux kernel multiple versions (affected in Linux 5.x, 6.x, and likely others where delegation timestamp support was added)

Timeline

  • 2026-09-11: disclosed: CVE-2026-89679 published
  • 2026-09-07: patched: Fix merged into stable kernel trees

References

Related threats