UNKNOWN NVD
CVE-2026-89699
In the Linux kernel, the following vulnerability has been resolved: nfsd: validate symlink target length in NFSv4 CREATE nfsd4_decode_create() accepts an unbo
In the Linux kernel, the following vulnerability has been resolved:
nfsd: validate symlink target length in NFSv4 CREATE
nfsd4_decode_create() accepts an unbounded cr_datalen from the wire for
NF4LNK symlink targets, allowing a client to force a kmalloc of up to
the maximum RPC payload size (several MiB) per COMPOUND op that persists
until compound teardown. The VFS rejects oversized targets with
ENAMETOOLONG, but the allocation has already occurred.
Reject cr_datalen == 0 early with nfserr_inval and cr_datalen greater
than NFS4_MAXPATHLEN (PATH_MAX) with nfserr_nametoolong to bound the
allocation.
References
- https://git.kernel.org/stable/c/041f57056e5fb9c80adc088269322d2c61074406
- https://git.kernel.org/stable/c/45ec115cbfecb4b3cfab7fca6f73d1b60696a25a
- https://git.kernel.org/stable/c/895a485cd3758031ef9993c0d53cf19ce8fb4ccc
- https://git.kernel.org/stable/c/b24843ea3de1676b29902457b38507c95a80649b
This unknown severity vulnerability was published on 2026-09-11 via NVD.
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.