CVE-2026-89698

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/09/2026
Last modified:
21/09/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> nfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage<br /> <br /> struct nfsd_genl_rqstp declares rq_daddr and rq_saddr as plain<br /> "struct sockaddr" (16 bytes). When an IPv6 NFS client is connected,<br /> nfsd_genl_rpc_status_compose_msg() casts these fields to<br /> "struct sockaddr_in6 *" (28 bytes) and reads sin6_addr at offset 8..24,<br /> which extends 8 bytes past the end of the 16-byte sockaddr field into<br /> the adjacent rq_flags member. The 16-byte nla_put_in6_addr then ships 8<br /> bytes of truncated IPv6 address followed by 8 bytes of rq_flags to<br /> userspace via the NFSD_A_RPC_STATUS_SADDR6/DADDR6 netlink attributes.<br /> <br /> This is reachable by any unprivileged process in the network namespace<br /> because NFSD_CMD_RPC_STATUS_GET uses GENL_CMD_CAP_DUMP without<br /> GENL_ADMIN_PERM.<br /> <br /> Fix by widening rq_daddr and rq_saddr to struct sockaddr_storage so the<br /> IPv6 casts operate within bounds, copying sizeof(struct sockaddr_storage)<br /> bytes in the memcpy calls so the full address is captured, and<br /> zero-initializing the genl_rqstp stack variable to prevent leaking<br /> uninitialized tail bytes through netlink.

Impact