From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5BF425328C6 for ; Fri, 11 Sep 2026 20:02:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156996; cv=none; b=jzTtGL7sNUGKZN8TDUjpx6KFSUfF5lA+f/259jV66JmWggW80kpYYVU89EMi9c7bNVrlqubaDYc5Za2eZS2jcJLbwVIl7ygfFj2TDLeCoGxaxlWc95kGUlaPVW3YXand5YHBt77NQU+xWmPdJOPjVzKkgjfG6aQuoqlH6dgSans= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156996; c=relaxed/simple; bh=k9XpdnYbkOsOkOZozOEYEwdeozEPVVf9Xf9I1MV2J2Y=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=X7NKWJ0JpGJmqsnHM3Kd/O3luhAsiadsZUVIVz1Om9typSxskfawpM9cEXyB/v5Rrgi/h6ccspAjeLG2e5TFDMmJy1wcYHJ98M6Vx4b2peBQLBKBhyBimCjL7P+MPlLUFwRtuSQ2aY1iXlN1yEIfdDDJ3p6F4PzhgxlPyixJqo0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=xFBFq6Ab; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="xFBFq6Ab" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 5C4261F00899; Fri, 11 Sep 2026 20:02:58 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156978; bh=7x+rE4Z8cfU8kS+TtZ7vagfNUVN0hKY4zoooADli4Us=; h=From:To:Cc:Subject:Date:Reply-To; b=xFBFq6Ab5siZDV6oCslaXDBi1rJlMtx/RDHfmtPMoHat2ts/Q9qxIvGr5mAiAL1/P SkVXxTu6QCYygH/oD2A/gudgfVXPaUFR64pLG0s1arH+iEb05CwBOAWruZl2FKMvKe HyOq4SvMN9gY7M8YpQppTHS/LCgXaZmOxvtjikys= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89695: nfsd: cap decoded POSIX ACL count to bound sort cost Date: Fri, 11 Sep 2026 21:46:24 +0200 Message-ID: <2026091154-CVE-2026-89695-0b51@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=2847; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=zE4mKzKqav633lYqRJKG1JtCwt3Js43eRoJKll5hwZc=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIpuiNl2psxRZ5H7ri0ODVs6czHdLqr/Fn9C3Pa7JO +Hbj7AFHbEsDIJMDLJiiixftvEc3V9xSNHL0PY0zBxWJpAhDFycAjARXzWG+VGx0o+8krdtK7Xb 1y6gLrP+8rd55gwLjne+zze2jHn0qG7Ly6fSGyRmC04vAwA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: nfsd: cap decoded POSIX ACL count to bound sort cost nfsd4_decode_posixacl() reads a u32 entry count off the wire and passes it straight to posix_acl_alloc() and sort_pacl_range(). The latter is an O(n^2) bubble sort, so a client-chosen count drives unbounded CPU in the server's compound processing path. nfsd4_decode_posixacl() xdr_stream_decode_u32(&count) /* uncapped u32 */ posix_acl_alloc(count, GFP_KERNEL) sort_pacl_range(*acl, 0, count - 1) /* O(n^2) bubble sort */ The encoder side in the same file already rejects ACLs whose a_count exceeds NFS_ACL_MAX_ENTRIES, but the decoder introduced in commit 5fc51dfc2eb1 ("NFSD: Add support for XDR decoding POSIX draft ACLs") omitted the symmetric check. Fix by rejecting a wire count greater than NFS_ACL_MAX_ENTRIES with nfserr_inval, before any allocation, so the sort is bounded by NFS_ACL_MAX_ENTRIES^2 comparisons. While we're in here, also fix the nfserr_resource return if posix_acl_alloc() fails. That's not a legal error code for v4.1+. Change it to return nfserr_jukebox as that's more appropriate for memory allocation failures. The Linux kernel CVE team has assigned CVE-2026-89695 to this issue. Affected and fixed versions =========================== Issue introduced in 7.0 with commit 5fc51dfc2eb160bd7ab3251ab1767cacf9c8bf05 and fixed in 7.2.4 with commit ea14d71d6ecb925673761bcf79f781f7dc9042cc Issue introduced in 7.0 with commit 5fc51dfc2eb160bd7ab3251ab1767cacf9c8bf05 and fixed in 7.3-rc1 with commit 4bc1108e876153a2dd6d874052b99182c3603135 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89695 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: fs/nfsd/nfs4xdr.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/ea14d71d6ecb925673761bcf79f781f7dc9042cc https://git.kernel.org/stable/c/4bc1108e876153a2dd6d874052b99182c3603135