← All Advisories

CVE-2026-89700

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-89700

Key Details

CVECVE-2026-89700
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

nfsd: validate sockaddr length per family in listener_set

nfsd_sock_nl_policy declares NFSD_A_SOCK_ADDR as a bare NLA_BINARY

attribute with no minimum length. A CAP_NET_ADMIN caller can send a

16-byte NFSD_A_SOCK_ADDR with sa_family=AF_INET6, causing a 12-byte

OOB read across three consumers (rpc_cmp_addr_port, svc_find_listener,

kernel_bind).

nfsd_nl_listener_set_doit() also parsed and validated each listener

entry inline in two separate loops, interleaved with mutating the

running listener configuration. The validation was duplicated, used an

open-coded "nla_len < sizeof(struct sockaddr)" check that was too short

for AF_INET6, and handled a malformed entry inconsistently depending on

which loop noticed it.

Add an nfsd_nl_validate_listeners() helper that walks the entire list

once and confirms each entry parses, carries both an address and a

transport name, and is long enough for its address family

(sizeof(struct sockaddr_in) for AF_INET, sizeof(struct sockaddr_in6)

for AF_INET6, -EAFNOSUPPORT otherwise). Call it before taking

nfsd_mutex or creating the serv, so a malformed request fails cleanly

with no side effects.

Since every entry is known valid by the time the two existing loops

run, drop the redundant presence and per-family length checks from

both, leaving only the nla_parse_nested() call needed to extract the

data. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-89700
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-89700