CVE-2026-89699

high

Description

In the Linux kernel, the following vulnerability has been resolved: nfsd: validate symlink target length in NFSv4 CREATE nfsd4_decode_create() accepts an unbounded cr_datalen from the wire for NF4LNK symlink targets, allowing a client to force a kmalloc of up to the maximum RPC payload size (several MiB) per COMPOUND op that persists until compound teardown. The VFS rejects oversized targets with ENAMETOOLONG, but the allocation has already occurred. Reject cr_datalen == 0 early with nfserr_inval and cr_datalen greater than NFS4_MAXPATHLEN (PATH_MAX) with nfserr_nametoolong to bound the allocation.

References

https://git.kernel.org/stable/c/b24843ea3de1676b29902457b38507c95a80649b

https://git.kernel.org/stable/c/895a485cd3758031ef9993c0d53cf19ce8fb4ccc

https://git.kernel.org/stable/c/888dad4b557352cf85be31613407b5ba51ad07d1

https://git.kernel.org/stable/c/8661d3cb38fd148947e57dbc0871fd4d3fa33bbf

https://git.kernel.org/stable/c/45ec115cbfecb4b3cfab7fca6f73d1b60696a25a

https://git.kernel.org/stable/c/3ef5e7a01a4d74995a65496bc9166d1e980a4355

https://git.kernel.org/stable/c/36011308b3f01ce7dc9954f3cefcbb5291af9f95

https://git.kernel.org/stable/c/041f57056e5fb9c80adc088269322d2c61074406

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-76611

Details

Source: Mitre, NVD

Published: 2026-09-11

Updated: 2026-09-14

Risk Information

CVSS v2

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

Severity: High

CVSS v3

Base Score: 7.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Severity: High

EPSS

EPSS: 0.00168