Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-89685

Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
11/09/2026
Última modificación:
21/09/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> nfsd: fix clock domain mismatch in clients_still_reclaiming()<br /> <br /> clients_still_reclaiming() computes a deadline from nn-&gt;boot_time<br /> (CLOCK_REALTIME, ~1.7 billion) but compares it against<br /> ktime_get_boottime_seconds() (CLOCK_BOOTTIME, seconds since boot).<br /> The comparison is always false — it would take ~54 years of uptime<br /> for BOOTTIME to exceed the REALTIME-derived deadline.<br /> <br /> This means any client can hold the server in grace indefinitely by<br /> sending CLAIM_PREVIOUS OPEN requests, blocking all non-reclaim<br /> operations for all other clients.<br /> <br /> Add boot_time_bt (CLOCK_BOOTTIME) alongside the existing boot_time<br /> and use it for the deadline computation. boot_time (CLOCK_REALTIME)<br /> is preserved for its cl_boot clientid-nonce role.