CVE-2026-89697High· 7.0▾ TwilightA flaw was found in the Linux kernel's Network File System Daemon (nfsd). When setting file attributes using `nfsd_proc_setattr()`, a specific code path (`BOTH_TIME_SET` branch) prematurely verifies file handles. This bypasses a critical w…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 38.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
— → 6.8
none → medium
— → 6.8
none → medium
— → 9.1
none → critical
9.1 → 6.8
critical → medium
6.8 → 9.1
medium → critical
Last analysed / modified upstream
0.2% → 0.7%
9.1 → 7
critical → high
A flaw was found in the Linux kernel's Network File System Daemon (nfsd). When setting file attributes using nfsd_proc_setattr(), a specific code path (BOTH_TIME_SET branch) prematurely verifies file handles. This bypasses a critical write verification step (fh_want_write()), allowing file attribute changes to proceed without a proper mount write reference. This could lead to unauthorized modification of file metadata or content, potentially impacting data integrity.
kernel: nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr() — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-15.
Affected:
No fix planned:
Not affected:
Out of support scope
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-89546Medium· 5.3kernel: Linux Kernel: Resource management flaw in SUNRPC NFS callback service (CVE-2026-89546)
CVE-2026-89646Medium· 5.5kernel: ceph: fix leaked inode reference on writeback abort at umount (CVE-2026-89646)
CVE-2026-89680High· 7.0kernel: nfsd: fix nfsd_file leak on inter-server COPY setup failure (CVE-2026-89680)
CVE-2026-89692Medium· 5.5kernel: nfsd: clear CALLBACK_RUNNING on failed delegation recall queue (CVE-2026-89692)
CVE-2026-89664High· 7.0kernel: nfsd: release OPEN-decoded posix ACLs via op_release (CVE-2026-89664)
CVE-2026-80983Medium· 5.5kernel: net/smc: fix socket refcount leak in smc_switch_conns() (CVE-2026-80983)