CVE-2026-89698
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
11/09/2026
Última modificación:
21/09/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
nfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage<br />
<br />
struct nfsd_genl_rqstp declares rq_daddr and rq_saddr as plain<br />
"struct sockaddr" (16 bytes). When an IPv6 NFS client is connected,<br />
nfsd_genl_rpc_status_compose_msg() casts these fields to<br />
"struct sockaddr_in6 *" (28 bytes) and reads sin6_addr at offset 8..24,<br />
which extends 8 bytes past the end of the 16-byte sockaddr field into<br />
the adjacent rq_flags member. The 16-byte nla_put_in6_addr then ships 8<br />
bytes of truncated IPv6 address followed by 8 bytes of rq_flags to<br />
userspace via the NFSD_A_RPC_STATUS_SADDR6/DADDR6 netlink attributes.<br />
<br />
This is reachable by any unprivileged process in the network namespace<br />
because NFSD_CMD_RPC_STATUS_GET uses GENL_CMD_CAP_DUMP without<br />
GENL_ADMIN_PERM.<br />
<br />
Fix by widening rq_daddr and rq_saddr to struct sockaddr_storage so the<br />
IPv6 casts operate within bounds, copying sizeof(struct sockaddr_storage)<br />
bytes in the memcpy calls so the full address is captured, and<br />
zero-initializing the genl_rqstp stack variable to prevent leaking<br />
uninitialized tail bytes through netlink.


