All of lore.kernel.org
 help / color / mirror / Atom feed
* CVE-2026-89700: nfsd: validate sockaddr length per family in listener_set
@ 2026-09-11 19:46 Greg Kroah-Hartman
  0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-11 19:46 UTC (permalink / raw)
  To: linux-cve-announce; +Cc: Greg Kroah-Hartman

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

nfsd: validate sockaddr length per family in listener_set

nfsd_sock_nl_policy declares NFSD_A_SOCK_ADDR as a bare NLA_BINARY
attribute with no minimum length. A CAP_NET_ADMIN caller can send a
16-byte NFSD_A_SOCK_ADDR with sa_family=AF_INET6, causing a 12-byte
OOB read across three consumers (rpc_cmp_addr_port, svc_find_listener,
kernel_bind).

nfsd_nl_listener_set_doit() also parsed and validated each listener
entry inline in two separate loops, interleaved with mutating the
running listener configuration. The validation was duplicated, used an
open-coded "nla_len < sizeof(struct sockaddr)" check that was too short
for AF_INET6, and handled a malformed entry inconsistently depending on
which loop noticed it.

Add an nfsd_nl_validate_listeners() helper that walks the entire list
once and confirms each entry parses, carries both an address and a
transport name, and is long enough for its address family
(sizeof(struct sockaddr_in) for AF_INET, sizeof(struct sockaddr_in6)
for AF_INET6, -EAFNOSUPPORT otherwise). Call it before taking
nfsd_mutex or creating the serv, so a malformed request fails cleanly
with no side effects.

Since every entry is known valid by the time the two existing loops
run, drop the redundant presence and per-family length checks from
both, leaving only the nla_parse_nested() call needed to extract the
data.

The Linux kernel CVE team has assigned CVE-2026-89700 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 6.10 with commit 16a471177496c8e04a9793812c187a2c1a2192fa and fixed in 6.18.50 with commit 2aca70c18c5f5d06004122861fb151d5fcc57faf
	Issue introduced in 6.10 with commit 16a471177496c8e04a9793812c187a2c1a2192fa and fixed in 7.2.4 with commit 22d0e4752ca88fd84196d22ebeedc905e6540440
	Issue introduced in 6.10 with commit 16a471177496c8e04a9793812c187a2c1a2192fa and fixed in 7.3-rc1 with commit bdcc85c2b05a9378d8bd2d65f9fc41440a3cf464

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-89700
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	fs/nfsd/nfsctl.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/2aca70c18c5f5d06004122861fb151d5fcc57faf
	https://git.kernel.org/stable/c/22d0e4752ca88fd84196d22ebeedc905e6540440
	https://git.kernel.org/stable/c/bdcc85c2b05a9378d8bd2d65f9fc41440a3cf464

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-09-11 20:03 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-11 19:46 CVE-2026-89700: nfsd: validate sockaddr length per family in listener_set Greg Kroah-Hartman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.