Junglewise Threat Intelligence

CVE-2026-89691: Linux kernel NFSv4 out-of-bounds read in compound arg release

CVE-2026-89691 · Severity: high · CVSS 7.1 · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's NFSv4 server (nfsd) contains a memory disclosure flaw in its network file sharing implementation. When handling NFSv4.1+ requests, stale metadata about processed operations is not properly cleared, allowing an attacker with network access to leak sensitive kernel memory to userspace via diagnostic interfaces. This could expose cryptographic keys, session tokens, or other confidential data stored in kernel memory.

Technical details

The vulnerability is an out-of-bounds (OOB) read in the nfsd4_release_compoundargs() function. When releasing compound RPC arguments, the code resets the ops buffer pointer to a small inline array (iops[8]) but fails to clear the opcnt field, which can retain values up to 200 for NFSv4.1+ compound operations. An attacker can trigger a race condition where rq_status_counter becomes stuck at an odd value, causing the RPC status netlink handler to read min(opcnt, 16) entries from the ops array. Since iops only has 8 elements, indices 8–15 access adjacent slab memory, exposing kernel heap contents. The fix unconditionally zeroes opcnt in nfsd4_release_compoundargs(), preventing any stale metadata leakage through the status interface. No authentication is required; the attacker needs only network access to an NFS server.

Affected products

  • Linux Linux kernel NFSv4-enabled kernels prior to patch (widely deployed across all stable versions)

Timeline

  • 2026-09-11: disclosed: Published in NVD
  • 2026-06-11: patched: Upstream patch committed by Jeff Layton
  • 2026-09-07: other: Backported to stable kernel branches by Greg Kroah-Hartman

References

Related threats