In the Linux kernel, the following vulnerability has been resolved:
nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo
nfsd4_ff_encode_getdeviceinfo() computes the da_addr_body reservation
as 16 + netid_len + addr_len, but the subsequent xdr_encode_opaque()
calls emit 8 + round_up(netid_len, 4) + round_up(addr_len, 4) bytes.
The mismatch means the declared da_addr_body length exceeds the actual
encoded data by 2-8 bytes on every flexfile GETDEVICEINFO reply,
leaking stale reply-page content to the client and mis-aligning the
subsequent version list decode.
Use xdr_align_size() for each string length to match what
xdr_encode_opaque() actually writes.
CVE-2026-89673
NONE
EPSS 0.21%
Updated Sep 14, 2026
Linux
https://git.kernel.org/stable/c/41ebca28e17f84293650598f86bd69532ec1a8e0
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/62e5949f0dd5ec837af144860ff908369df4c7c9
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/74015b7be806ad9e21d46f7bd2831df280c6c783
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/8b989aaec85e1293a871d602590c951fe44b8647
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/88bce7e326c368d7df15126ccac537e54bebd467
416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVE Details
CVE ID
CVE-2026-89673
Published Date
Sep 11, 2026
Vendor
Linux
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.21%
Likelihood of exploitation in next 30 days
Percentile:
10.1th percentile (higher than 10.1% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory