From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 45B9E58F09F for ; Fri, 11 Sep 2026 20:03:15 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789157011; cv=none; b=W/SUztUsCze3tRPswPe0bTuoN47ay/fTNBNbSiupYng6tMgkZpfx6qdWpJu52r9/HxGK2Z8OokAXanjNBl8GQZPLzwaWiI1KB95lc9F6Rw24m5vXvMUKSUk7QhKJeLGsAI3osCUPw/RvL2dzr9uTLfDSnxSVsEhJ0ENLwcxPVr0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789157011; c=relaxed/simple; bh=PHuWyqxwY306p6atHr2vExAUton7o+Be99ltJRAKnqU=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=GgVPqNu5S/G1KUIAncFJi5huKITRXzEA8s1ufGv8H6w3EyQTdThqA6vjZfgv598ts0oEeg3ea333PAoFUNr7kZCzXD5iPV2m6/RNtl29kMAz5YKSBM9+EgX5sYVReqjRGeFe4ELsclVHnC5asSZnGfRCzHgFTsJddUl0r4Q6Ck0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=CkjpJ79b; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="CkjpJ79b" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 7648B1F00898; Fri, 11 Sep 2026 20:03:11 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156992; bh=eKAgPK/SD1q22+P/zqEfhIwHTNiWSl1PF5RN74WO/NM=; h=From:To:Cc:Subject:Date:Reply-To; b=CkjpJ79bH5W4dMYGmHzzJyx6KQqS7aYz013PT2u/cfoHJ6LroIjb7wfLGcPYkkBBk Hyth+w4IIbl+2psgXWy1EYeCD8mQhB4B1qgQrBq+Hg0KmTdvwoWkxp6kjciMrGZzbN 4NsxKGG7CSJHn8P7xBY0iK7FzdA4utT2JV3H15JU= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89666: nfsd: reject out-of-range nseconds in NFSv3 SETATTR and create ops Date: Fri, 11 Sep 2026 21:45:55 +0200 Message-ID: <2026091147-CVE-2026-89666-17d6@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=4569; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=pbF3/gnHcZJmEpxPk6NlTE3wqC9HU89muukRY/P4Pa0=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIqvfRRs+O1Yz8fre6Bf6gl9Yzs7cUPTSh38Fd5LFw lhdqxCrjlgWBkEmBlkxRZYv23iO7q84pOhlaHsaZg4rE8gQBi5OAZjIDVOGOZznXxi8PMd41O9W 84wnj1e++cil/Yphnv5MTrmID19DxLLdbrOZ/75mqM4vDAA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: nfsd: reject out-of-range nseconds in NFSv3 SETATTR and create ops A client can send an NFSv3 SETATTR, CREATE, MKDIR, SYMLINK or MKNOD carrying an atime or mtime whose nseconds field is out of range. The value is well-formed on the wire and decodes cleanly into a valid uint32, but it is not a valid timespec64: tv_nsec must be less than NSEC_PER_SEC. Nothing in the setattr path clamps it. notify_change() runs the time through timestamp_truncate(), which does not reduce tv_nsec below NSEC_PER_SEC when the filesystem supports nanosecond granularity (s_time_gran == 1), and the inode atime/mtime setters store it verbatim (only ctime is normalized, via inode_set_ctime_to_ts()). The un-normalized value then corrupts on-disk metadata: ext4's ext4_encode_extra_time() shifts tv_nsec left by EXT4_EPOCH_BITS, which overflows the 32-bit extra field and clobbers the seconds-epoch bits, so the stored seconds (and thus the year) are wrong on read-back. XFS with bigtime mis-stores the timestamp for the same reason. Validate the client-supplied atime/mtime in the proc handlers and return NFS3ERR_INVAL before anything is changed. RFC 1813 lists NFS3ERR_INVAL for SETATTR and describes it as the error for a value the server 'can not store ... in its own representation'; the client maps it to EINVAL. Checking in the proc handlers, rather than in nfsd_setattr(), keeps the rejection in front of object creation. The create operations create the object before nfsd_create_setattr() runs, so a late failure would leave the new object behind and turn a non-idempotent request into a namespace change that reports failure. The check is therefore done up front, for the create operations before the object is created. tv_nsec is a long, so the comparison casts it to unsigned long (the same width) rather than to u32, matching timespec64_valid(). A u32 cast would truncate on 64-bit; the unsigned long cast also rejects a value that became negative when an out-of-range u32 wire nseconds was assigned to a 32-bit long. Only client-supplied times are checked: SET_TO_SERVER_TIME requests carry no client value. The sattrguard3 ctime is deliberately left alone: an out-of-range guard simply never matches the object's ctime and yields NFS3ERR_NOT_SYNC via the existing guardtime comparison, which is the protocol-correct outcome rather than rejecting the request. The Linux kernel CVE team has assigned CVE-2026-89666 to this issue. Affected and fixed versions =========================== Issue introduced in 2.6.12 with commit 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and fixed in 6.12.109 with commit 55341d8a5a0f5853e70d46f5a55cf06007808f1d Issue introduced in 2.6.12 with commit 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and fixed in 6.18.50 with commit 54e02f5e32c52fb395f2ee02986a6c6d5608d22b Issue introduced in 2.6.12 with commit 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and fixed in 7.2.4 with commit e2543852152bcf9aeb57da17d9f9219f7df8aafb Issue introduced in 2.6.12 with commit 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and fixed in 7.3-rc1 with commit eb0eca7720662ba5847df1510e73801f7f473094 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89666 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: fs/nfsd/nfs3proc.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/55341d8a5a0f5853e70d46f5a55cf06007808f1d https://git.kernel.org/stable/c/54e02f5e32c52fb395f2ee02986a6c6d5608d22b https://git.kernel.org/stable/c/e2543852152bcf9aeb57da17d9f9219f7df8aafb https://git.kernel.org/stable/c/eb0eca7720662ba5847df1510e73801f7f473094