{"id":"CVE-2026-89674","title":"kernel: nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget (CVE-2026-89674)","summary":"A flaw was found in the `nfsd` component of the Linux kernel. Incorrect calculations in the XDR (External Data Representation) buffer size within the `nfsd4_ff_encode_layoutget()` function can lead to two critical issues. An attacker could…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-805","vendor":"Red Hat","product":"Linux","affected":["Linux >= 9b9960a0ca4773e21c4b153ed355583946346b25 < 3a7fd224df0fbb42167eb1b77be45d72fe0b1098","Linux >= 9b9960a0ca4773e21c4b153ed355583946346b25 < 29e4478e2ed5a227e8f0c33cacb91bf227cedd47","Linux >= 9b9960a0ca4773e21c4b153ed355583946346b25 < 65a72b721943618eeb3a41c8b36e915591f3f83f","Linux >= 9b9960a0ca4773e21c4b153ed355583946346b25 < bee826c00ac900473f91306f1f3e5a5a81fd4a74","Linux >= 9b9960a0ca4773e21c4b153ed355583946346b25 < e7d9d23ecd9172f05b09bb678ff22db8e361c428","Linux >= 9b9960a0ca4773e21c4b153ed355583946346b25 < 0380129b1373c437eb35401a174671c8888f4b80","Linux >= 9b9960a0ca4773e21c4b153ed355583946346b25 < c81cef6a805dec266c10fc4f83c93d6fcf1a2b43","Linux >= 9b9960a0ca4773e21c4b153ed355583946346b25 < f9868174af49d207fbaf0c5e055d088a983684af","Linux 4.8"],"published":"2026-09-11","updated":"2026-09-16","sourceUpdated":"2026-09-16T14:15:10+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89674.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89674.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89674"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532385"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89674"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89674"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89674.mbox"},{"url":"https://git.kernel.org/stable/c/3a7fd224df0fbb42167eb1b77be45d72fe0b1098"},{"url":"https://git.kernel.org/stable/c/29e4478e2ed5a227e8f0c33cacb91bf227cedd47"},{"url":"https://git.kernel.org/stable/c/65a72b721943618eeb3a41c8b36e915591f3f83f"},{"url":"https://git.kernel.org/stable/c/bee826c00ac900473f91306f1f3e5a5a81fd4a74"},{"url":"https://git.kernel.org/stable/c/e7d9d23ecd9172f05b09bb678ff22db8e361c428"},{"url":"https://git.kernel.org/stable/c/0380129b1373c437eb35401a174671c8888f4b80"},{"url":"https://git.kernel.org/stable/c/c81cef6a805dec266c10fc4f83c93d6fcf1a2b43"},{"url":"https://git.kernel.org/stable/c/f9868174af49d207fbaf0c5e055d088a983684af"}],"tags":["csaf","vex","red-hat","cve.org","score-dispute"],"epss":0.00521,"epssPercentile":0.43043,"scores":{"vendor":5.5,"cna":9.8},"ingestedAt":"2026-09-14T15:23:07.450Z","slug":"CVE-2026-89674","body":"## Overview\n\nA flaw was found in the `nfsd` component of the Linux kernel. Incorrect calculations in the XDR (External Data Representation) buffer size within the `nfsd4_ff_encode_layoutget()` function can lead to two critical issues. An attacker could potentially exploit this to write data beyond the intended memory boundaries, which might result in system instability or denial of service. Additionally, this flaw could cause the system to expose sensitive, uninitialized kernel memory to a client, leading to information disclosure.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · updated 2026-09-16 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89674.json)\n\n**kernel: nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-16.\n\nNot affected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nRefer to the advisory for fix availability.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":205436,"id":"CVE-2026-89674","ts":1789576713761,"field":"cvss","old":"9.8","new":"5.5"},{"seq":205435,"id":"CVE-2026-89674","ts":1789576713761,"field":"severity","old":"critical","new":"medium"},{"seq":197760,"id":"CVE-2026-89674","ts":1789384318734,"field":"cvss","old":"7.5","new":"9.8"},{"seq":197759,"id":"CVE-2026-89674","ts":1789384318734,"field":"severity","old":"high","new":"critical"},{"seq":183691,"id":"CVE-2026-89674","ts":1789356676968,"field":"cvss","old":"9.8","new":"7.5"},{"seq":183690,"id":"CVE-2026-89674","ts":1789356676968,"field":"severity","old":"critical","new":"high"},{"seq":153540,"id":"CVE-2026-89674","ts":1789285351206,"field":"cvss","old":null,"new":"9.8"},{"seq":153539,"id":"CVE-2026-89674","ts":1789285351206,"field":"severity","old":"none","new":"critical"},{"seq":147297,"id":"CVE-2026-89674","ts":1789270207946,"field":"cvss","old":null,"new":"7.5"},{"seq":147296,"id":"CVE-2026-89674","ts":1789270207946,"field":"severity","old":"none","new":"high"},{"seq":109054,"id":"CVE-2026-89674","ts":1789183730128,"field":"cvss","old":null,"new":"7.5"},{"seq":109053,"id":"CVE-2026-89674","ts":1789183730128,"field":"severity","old":"none","new":"high"}]}