CVE-2026-89678High· 7.0▾ TwilightA flaw was found in the Linux kernel's Network File System (NFS) daemon (nfsd) component. The `nfsd_direct_write()` function, responsible for handling direct writes, incorrectly detects partial writes. This issue occurs because the logic f…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 38.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
0.2% → 0.4%
— → 6.8
none → medium
— → 7.5
none → high
7.5 → 6.8
high → medium
6.8 → 7.5
medium → high
7.5 → 6.8
high → medium
Last analysed / modified upstream
6.8 → 7
medium → high
A flaw was found in the Linux kernel's Network File System (NFS) daemon (nfsd) component. The nfsd_direct_write() function, responsible for handling direct writes, incorrectly detects partial writes. This issue occurs because the logic for detecting short writes compares the actual bytes written against a residual count rather than the original requested length. As a result, partial writes between 50% and 99% of the intended size are not properly identified, leading to subsequent data being written at incorrect file offsets and the NFS client receiving an inaccurate report of bytes written. This can allow a remote attacker to cause data corruption on the NFS server.
kernel: nfsd: fix partial-write detection in nfsd_direct_write — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-21.
Affected:
No fix planned:
Not affected:
Out of support scope
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-59982High· 7.1OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry
CVE-2026-80997Medium· 5.5kernel: net: ipa: fix stalled modem TX queue after runtime resume (CVE-2026-80997)
CVE-2026-89500High· 7.0kernel: ring-buffer: Make cpu_buffer::free_page a buffer_data_read_page (CVE-2026-89500)
CVE-2026-89501High· 7.0kernel: ring-buffer: Hold cpu_buffer::lock when resizing a subbuf (CVE-2026-89501)
CVE-2026-89503Medium· 5.5kernel: ring-buffer: Fix subbuf resize race with ring_buffer_alloc_read_page() (CVE-2026-89503)
CVE-2026-89521Medium· 5.5kernel: sched/core: Handle pick_task() releasing the rq lock (CVE-2026-89521)