{"api_version":"1","generated_at":"2026-09-12T04:34:19+00:00","cve":"CVE-2026-89673","urls":{"html":"https://cve.report/CVE-2026-89673","api":"https://cve.report/api/cve/CVE-2026-89673.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-89673","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-89673"},"summary":{"title":"nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: fix XDR padding calculation in ff_encode_getdeviceinfo\n\nnfsd4_ff_encode_getdeviceinfo() computes the da_addr_body reservation\nas 16 + netid_len + addr_len, but the subsequent xdr_encode_opaque()\ncalls emit 8 + round_up(netid_len, 4) + round_up(addr_len, 4) bytes.\nThe mismatch means the declared da_addr_body length exceeds the actual\nencoded data by 2-8 bytes on every flexfile GETDEVICEINFO reply,\nleaking stale reply-page content to the client and mis-aligning the\nsubsequent version list decode.\n\nUse xdr_align_size() for each string length to match what\nxdr_encode_opaque() actually writes.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-11 20:19:53","updated_at":"2026-09-11 20:19:53"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/62e5949f0dd5ec837af144860ff908369df4c7c9","name":"https://git.kernel.org/stable/c/62e5949f0dd5ec837af144860ff908369df4c7c9","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/74015b7be806ad9e21d46f7bd2831df280c6c783","name":"https://git.kernel.org/stable/c/74015b7be806ad9e21d46f7bd2831df280c6c783","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/41ebca28e17f84293650598f86bd69532ec1a8e0","name":"https://git.kernel.org/stable/c/41ebca28e17f84293650598f86bd69532ec1a8e0","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/8b989aaec85e1293a871d602590c951fe44b8647","name":"https://git.kernel.org/stable/c/8b989aaec85e1293a871d602590c951fe44b8647","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89673","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89673","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected efcae97fa425ca6db9d126e37daccf2d7225cb09 74015b7be806ad9e21d46f7bd2831df280c6c783 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected efcae97fa425ca6db9d126e37daccf2d7225cb09 41ebca28e17f84293650598f86bd69532ec1a8e0 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected efcae97fa425ca6db9d126e37daccf2d7225cb09 62e5949f0dd5ec837af144860ff908369df4c7c9 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected efcae97fa425ca6db9d126e37daccf2d7225cb09 8b989aaec85e1293a871d602590c951fe44b8647 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.4.16 6.12.109 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.4.16 6.18.50 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.4.16 7.2.4 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.4.16 7.3-rc1 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["fs/nfsd/flexfilelayoutxdr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"74015b7be806ad9e21d46f7bd2831df280c6c783","status":"affected","version":"efcae97fa425ca6db9d126e37daccf2d7225cb09","versionType":"git"},{"lessThan":"41ebca28e17f84293650598f86bd69532ec1a8e0","status":"affected","version":"efcae97fa425ca6db9d126e37daccf2d7225cb09","versionType":"git"},{"lessThan":"62e5949f0dd5ec837af144860ff908369df4c7c9","status":"affected","version":"efcae97fa425ca6db9d126e37daccf2d7225cb09","versionType":"git"},{"lessThan":"8b989aaec85e1293a871d602590c951fe44b8647","status":"affected","version":"efcae97fa425ca6db9d126e37daccf2d7225cb09","versionType":"git"}]},{"defaultStatus":"unaffected","product":"Linux","programFiles":["fs/nfsd/flexfilelayoutxdr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"6.12.109","status":"affected","version":"6.4.16","versionType":"semver"},{"lessThan":"6.18.50","status":"affected","version":"6.4.16","versionType":"semver"},{"lessThan":"7.2.4","status":"affected","version":"6.4.16","versionType":"semver"},{"lessThan":"7.3-rc1","status":"affected","version":"6.4.16","versionType":"semver"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.109","versionStartIncluding":"6.4.16","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.50","versionStartIncluding":"6.4.16","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.4","versionStartIncluding":"6.4.16","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"6.4.16","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: fix XDR padding calculation in ff_encode_getdeviceinfo\n\nnfsd4_ff_encode_getdeviceinfo() computes the da_addr_body reservation\nas 16 + netid_len + addr_len, but the subsequent xdr_encode_opaque()\ncalls emit 8 + round_up(netid_len, 4) + round_up(addr_len, 4) bytes.\nThe mismatch means the declared da_addr_body length exceeds the actual\nencoded data by 2-8 bytes on every flexfile GETDEVICEINFO reply,\nleaking stale reply-page content to the client and mis-aligning the\nsubsequent version list decode.\n\nUse xdr_align_size() for each string length to match what\nxdr_encode_opaque() actually writes."}],"providerMetadata":{"dateUpdated":"2026-09-11T19:45:58.149Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/74015b7be806ad9e21d46f7bd2831df280c6c783"},{"url":"https://git.kernel.org/stable/c/41ebca28e17f84293650598f86bd69532ec1a8e0"},{"url":"https://git.kernel.org/stable/c/62e5949f0dd5ec837af144860ff908369df4c7c9"},{"url":"https://git.kernel.org/stable/c/8b989aaec85e1293a871d602590c951fe44b8647"}],"title":"nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-89673","datePublished":"2026-09-11T19:45:58.149Z","dateReserved":"2026-09-11T19:38:34.746Z","dateUpdated":"2026-09-11T19:45:58.149Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-11 20:19:53","lastModifiedDate":"2026-09-11 20:19:53","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"89673","Ordinal":"1","Title":"nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo","CVE":"CVE-2026-89673","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"89673","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: fix XDR padding calculation in ff_encode_getdeviceinfo\n\nnfsd4_ff_encode_getdeviceinfo() computes the da_addr_body reservation\nas 16 + netid_len + addr_len, but the subsequent xdr_encode_opaque()\ncalls emit 8 + round_up(netid_len, 4) + round_up(addr_len, 4) bytes.\nThe mismatch means the declared da_addr_body length exceeds the actual\nencoded data by 2-8 bytes on every flexfile GETDEVICEINFO reply,\nleaking stale reply-page content to the client and mis-aligning the\nsubsequent version list decode.\n\nUse xdr_align_size() for each string length to match what\nxdr_encode_opaque() actually writes.","Type":"Description","Title":"nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo"}]}}}