← All Advisories

CVE-2026-89698

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-89698

Key Details

CVECVE-2026-89698
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

nfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage

struct nfsd_genl_rqstp declares rq_daddr and rq_saddr as plain

"struct sockaddr" (16 bytes). When an IPv6 NFS client is connected,

nfsd_genl_rpc_status_compose_msg() casts these fields to

"struct sockaddr_in6 *" (28 bytes) and reads sin6_addr at offset 8..24,

which extends 8 bytes past the end of the 16-byte sockaddr field into

the adjacent rq_flags member. The 16-byte nla_put_in6_addr then ships 8

bytes of truncated IPv6 address followed by 8 bytes of rq_flags to

userspace via the NFSD_A_RPC_STATUS_SADDR6/DADDR6 netlink attributes.

This is reachable by any unprivileged process in the network namespace

because NFSD_CMD_RPC_STATUS_GET uses GENL_CMD_CAP_DUMP without

GENL_ADMIN_PERM.

Fix by widening rq_daddr and rq_saddr to struct sockaddr_storage so the

IPv6 casts operate within bounds, copying sizeof(struct sockaddr_storage)

bytes in the memcpy calls so the full address is captured, and

zero-initializing the genl_rqstp stack variable to prevent leaking

uninitialized tail bytes through netlink. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-89698
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-89698