nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo
Published Sep 11, 2026
5.5
MEDIUMCVSS 3.1
EPSS 0.21%
Description
nfsd4_ff_encode_getdeviceinfo() computes the da_addr_body reservation as 16 + netid_len + addr_len, but the subsequent xdr_encode_opaque() calls emit 8 + round_up(netid_len, 4) + round_up(addr_len, 4) bytes. The mismatch means the declared da_addr_body length exceeds the actual encoded data by 2-8 bytes on every flexfile GETDEVICEINFO reply, leaking stale reply-page content to the client and mis-aligning the subsequent version list decode.
Use xdr_align_size() for each string length to match what xdr_encode_opaque() actually writes.
Affected products
-
Affected
- ≥ 6.4.16, < 6.12.109
- ≥ 6.4.16, < 6.18.50
- ≥ 6.4.16, < 6.6.157
- ≥ 6.4.16, < 7.2.4
- ≥ 6.4.16, < 7.3-rc1
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
No data.
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 10
kernel-rt
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 10 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (11)
- https://access.redhat.com/security/cve/CVE-2026-89673 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2532322 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-76585 Advisory
- https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89673.mbox
- https://git.kernel.org/stable/c/41ebca28e17f84293650598f86bd69532ec1a8e0
- https://git.kernel.org/stable/c/62e5949f0dd5ec837af144860ff908369df4c7c9
- https://git.kernel.org/stable/c/74015b7be806ad9e21d46f7bd2831df280c6c783
- https://git.kernel.org/stable/c/88bce7e326c368d7df15126ccac537e54bebd467
- https://git.kernel.org/stable/c/8b989aaec85e1293a871d602590c951fe44b8647
- https://nvd.nist.gov/vuln/detail/CVE-2026-89673
- https://www.cve.org/CVERecord?id=CVE-2026-89673
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data