CVE-2026-89674Medium· 5.5▾ SunlitA flaw was found in the `nfsd` component of the Linux kernel. Incorrect calculations in the XDR (External Data Representation) buffer size within the `nfsd4_ff_encode_layoutget()` function can lead to two critical issues. An attacker could…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
— → 7.5
none → high
— → 7.5
none → high
— → 9.8
none → critical
9.8 → 7.5
critical → high
7.5 → 9.8
high → critical
0.2% → 0.5%
Last analysed / modified upstream
9.8 → 5.5
critical → medium
A flaw was found in the nfsd component of the Linux kernel. Incorrect calculations in the XDR (External Data Representation) buffer size within the nfsd4_ff_encode_layoutget() function can lead to two critical issues. An attacker could potentially exploit this to write data beyond the intended memory boundaries, which might result in system instability or denial of service. Additionally, this flaw could cause the system to expose sensitive, uninitialized kernel memory to a client, leading to information disclosure.
kernel: nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-16.
Not affected:
Refer to the advisory for fix availability.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-89719Medium· 4.1In the Linux kernel, the following vulnerability has been resolved: zram: fix out-of-bounds access in read_block_state() read_block_state() calculates nr_pages before taking dev_lock
CVE-2026-80945Critical· 9.1In the Linux kernel, the following vulnerability has been resolved: crypto: iaa - unmap dst before software fallback on decompress On a hardware analytics error, decompress retries through the software fallback, which writes req->dst w…
CVE-2026-89492Critical· 9.8In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate directory-index entry counts when reading metadata ocfs2_validate_dx_leaf() and ocfs2_validate_dx_root() check the ECC and signature of an indexed-dire…
CVE-2026-89544High· 7.5In the Linux kernel, the following vulnerability has been resolved: SUNRPC: fix gssx_dec_option_array error path bugs Four coupled defects in the gssx XDR option-array decoder make the error paths unsafe: a NULL deref in the caller, a …
CVE-2026-89561High· 7.5In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv() ipv6_rpl_srh_rcv() dereferences idev from __in6_dev_get() without a NULL check when reading idev->cnf.rpl…
CVE-2026-89622High· 7.8In the Linux kernel, the following vulnerability has been resolved: HID: mcp2221: clear rxbuf after I2C/SMBus transfer completes mcp_i2c_smbus_read() stores the caller-supplied buffer pointer in mcp->rxbuf for the duration of a transfe…