---
id: CVE-2026-89674
title: >-
  kernel: nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget
  (CVE-2026-89674)
summary: >-
  A flaw was found in the `nfsd` component of the Linux kernel. Incorrect
  calculations in the XDR (External Data Representation) buffer size within the
  `nfsd4_ff_encode_layoutget()` function can lead to two critical issues. An
  attacker could…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-805
vendor: Red Hat
product: Linux
affected:
  - >-
    Linux >= 9b9960a0ca4773e21c4b153ed355583946346b25 <
    3a7fd224df0fbb42167eb1b77be45d72fe0b1098
  - >-
    Linux >= 9b9960a0ca4773e21c4b153ed355583946346b25 <
    29e4478e2ed5a227e8f0c33cacb91bf227cedd47
  - >-
    Linux >= 9b9960a0ca4773e21c4b153ed355583946346b25 <
    65a72b721943618eeb3a41c8b36e915591f3f83f
  - >-
    Linux >= 9b9960a0ca4773e21c4b153ed355583946346b25 <
    bee826c00ac900473f91306f1f3e5a5a81fd4a74
  - >-
    Linux >= 9b9960a0ca4773e21c4b153ed355583946346b25 <
    e7d9d23ecd9172f05b09bb678ff22db8e361c428
  - >-
    Linux >= 9b9960a0ca4773e21c4b153ed355583946346b25 <
    0380129b1373c437eb35401a174671c8888f4b80
  - >-
    Linux >= 9b9960a0ca4773e21c4b153ed355583946346b25 <
    c81cef6a805dec266c10fc4f83c93d6fcf1a2b43
  - >-
    Linux >= 9b9960a0ca4773e21c4b153ed355583946346b25 <
    f9868174af49d207fbaf0c5e055d088a983684af
  - Linux 4.8
published: '2026-09-11'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T14:15:10+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89674.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89674.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-89674'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2532385'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-89674'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89674'
  - url: >-
      https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89674.mbox
  - url: 'https://git.kernel.org/stable/c/3a7fd224df0fbb42167eb1b77be45d72fe0b1098'
  - url: 'https://git.kernel.org/stable/c/29e4478e2ed5a227e8f0c33cacb91bf227cedd47'
  - url: 'https://git.kernel.org/stable/c/65a72b721943618eeb3a41c8b36e915591f3f83f'
  - url: 'https://git.kernel.org/stable/c/bee826c00ac900473f91306f1f3e5a5a81fd4a74'
  - url: 'https://git.kernel.org/stable/c/e7d9d23ecd9172f05b09bb678ff22db8e361c428'
  - url: 'https://git.kernel.org/stable/c/0380129b1373c437eb35401a174671c8888f4b80'
  - url: 'https://git.kernel.org/stable/c/c81cef6a805dec266c10fc4f83c93d6fcf1a2b43'
  - url: 'https://git.kernel.org/stable/c/f9868174af49d207fbaf0c5e055d088a983684af'
tags:
  - csaf
  - vex
  - red-hat
  - cve.org
  - score-dispute
epss: 0.00521
epssPercentile: 0.43236
scores:
  vendor: 5.5
  cna: 9.8
ingestedAt: '2026-09-14T15:23:07.450Z'
---

## Overview

A flaw was found in the `nfsd` component of the Linux kernel. Incorrect calculations in the XDR (External Data Representation) buffer size within the `nfsd4_ff_encode_layoutget()` function can lead to two critical issues. An attacker could potentially exploit this to write data beyond the intended memory boundaries, which might result in system instability or denial of service. Additionally, this flaw could cause the system to expose sensitive, uninitialized kernel memory to a client, leading to information disclosure.

## Vendor advisories

- **Red Hat VEX** · Moderate · updated 2026-09-16 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89674.json)

**kernel: nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-16.

Not affected:

- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 4

## Remediation

Refer to the advisory for fix availability.
