{"id":"CVE-2026-89678","title":"kernel: nfsd: fix partial-write detection in nfsd_direct_write (CVE-2026-89678)","summary":"A flaw was found in the Linux kernel's Network File System (NFS) daemon (nfsd) component. The `nfsd_direct_write()` function, responsible for handling direct writes, incorrectly detects partial writes. This issue occurs because the logic f…","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-823","vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","affected":["enterprise_linux 10","enterprise_linux 6"],"published":"2026-09-11","updated":"2026-09-21","sourceUpdated":"2026-09-21T09:50:07+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89678.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89678.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89678"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532180"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89678"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89678"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89678.mbox"},{"url":"https://git.kernel.org/stable/c/250ec14932d5cfe102f68a57892bb566eee7f83e"},{"url":"https://git.kernel.org/stable/c/fa6590dfd16ab55f03b658b079072ace3504825e"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00354,"epssPercentile":0.29194,"scores":{"vendor":6.8,"cna":7.5},"ingestedAt":"2026-09-14T15:23:07.473Z","slug":"CVE-2026-89678","body":"## Overview\n\nA flaw was found in the Linux kernel's Network File System (NFS) daemon (nfsd) component. The `nfsd_direct_write()` function, responsible for handling direct writes, incorrectly detects partial writes. This issue occurs because the logic for detecting short writes compares the actual bytes written against a residual count rather than the original requested length. As a result, partial writes between 50% and 99% of the intended size are not properly identified, leading to subsequent data being written at incorrect file offsets and the NFS client receiving an inaccurate report of bytes written. This can allow a remote attacker to cause data corruption on the NFS server.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89678.json)\n\n**kernel: nfsd: fix partial-write detection in nfsd_direct_write** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-21.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 10\n\nNot affected:\n\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nOut of support scope","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":208494,"id":"CVE-2026-89678","ts":1790005720714,"field":"cvss","old":"6.8","new":"7"},{"seq":208493,"id":"CVE-2026-89678","ts":1790005720714,"field":"severity","old":"medium","new":"high"},{"seq":202986,"id":"CVE-2026-89678","ts":1789403733236,"field":"cvss","old":"7.5","new":"6.8"},{"seq":202985,"id":"CVE-2026-89678","ts":1789403733236,"field":"severity","old":"high","new":"medium"},{"seq":197748,"id":"CVE-2026-89678","ts":1789384318684,"field":"cvss","old":"6.8","new":"7.5"},{"seq":197747,"id":"CVE-2026-89678","ts":1789384318684,"field":"severity","old":"medium","new":"high"},{"seq":183683,"id":"CVE-2026-89678","ts":1789356676934,"field":"cvss","old":"7.5","new":"6.8"},{"seq":183682,"id":"CVE-2026-89678","ts":1789356676934,"field":"severity","old":"high","new":"medium"},{"seq":153548,"id":"CVE-2026-89678","ts":1789285351238,"field":"cvss","old":null,"new":"7.5"},{"seq":153547,"id":"CVE-2026-89678","ts":1789285351238,"field":"severity","old":"none","new":"high"},{"seq":147626,"id":"CVE-2026-89678","ts":1789270211647,"field":"cvss","old":null,"new":"6.8"},{"seq":147625,"id":"CVE-2026-89678","ts":1789270211647,"field":"severity","old":"none","new":"medium"},{"seq":109382,"id":"CVE-2026-89678","ts":1789183731690,"field":"cvss","old":null,"new":"6.8"},{"seq":109381,"id":"CVE-2026-89678","ts":1789183731690,"field":"severity","old":"none","new":"medium"}]}