From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0D25C44E045 for ; Fri, 11 Sep 2026 20:03:47 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789157035; cv=none; b=p2RH7NOfS+mi1GK6jJ8yuVqmvNNYEuwYBa6vhyJgNOoqdzPNEASkK0PSJ01UXr041SHxedqZb2TJbPQGhs0W1I4LMAzleYg4zZBZdPdSYN2uc0enEDZ8rzQE363ypWXt8/mYGApSRv5RL0C3cgw5t9KGikYGe1icv1O6gR4RXYE= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789157035; c=relaxed/simple; bh=hH4Z17ezJZfQ4eP1jEL9sEf8l8ycNxTaHBKX0JEm5Mw=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=ZClAHgyb03xMDlq4E7WkQgxQ/LCY+cl6oPy2n0+X6t3AAv76mB6mrI9JpNMaYv4Fk0LJnGW6z1R9RoIKzovCKmkz1y+BlkhR2pZYPm0AEqN6e8OgEXkaj7xlEIDXNYnSXtEyYp5erwts5AqeF008mGIAg9MNPjBlD1rLajNP4R4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=Igja+pjp; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="Igja+pjp" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 24A7E1F00893; Fri, 11 Sep 2026 20:03:46 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789157027; bh=8OYfR5oJAMfrJEG6TNTik9LJUdECQgTS+24PDWAPQTY=; h=From:To:Cc:Subject:Date:Reply-To; b=Igja+pjpmzDD/fShpQqSkZwob/74c9fxShKpLuT7Ynnv+Jq7CV5ARiOnJC2uuCo8l OIUy5wu77M9IDccpxINqhrqC7GSsg8fcF+r7MIMqhtV+OfK9HiZAzdGbNnjB9jIWt0 /i7lOI5lLYC30SZkjdwyPbd8AF4isHWNOWYqlBiE= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89713: NFSD: check truncate permission under inode lock Date: Fri, 11 Sep 2026 21:46:42 +0200 Message-ID: <2026091158-CVE-2026-89713-a846@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3727; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=4uus5LhOGLbS+P3YHAt9BquZFMO6OFFcJeZVV/UtpV0=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLItsuH3E5/ihiPtv/dbPLfhsHCC5h2HNpsXJvDueqb eeqK9dKdMSyMAgyMciKKbJ82cZzdH/FIUUvQ9vTMHNYmUCGMHBxCsBEZi1gWHA2a8qu8ssKcnFr +V/damY6s/ORUz/DgivzF4cxL2o6yjnr+uF7218+fKQ1bSYA X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: NFSD: check truncate permission under inode lock nfsd_setattr() checks whether a size update needs NFSD_MAY_TRUNC before it takes inode_lock(). The comparison uses the file size sampled by that unlocked read, but the actual ATTR_SIZE update is applied later under inode_lock() by notify_change(). This leaves a TOCTOU window for append-only files. If a client sends a SETATTR that does not shrink the file at the time of the unlocked sample, a concurrent append can extend the file before nfsd_setattr() takes inode_lock(). notify_change() then applies a real truncation without the NFSD_MAY_TRUNC check that rejects IS_APPEND(inode). The VFS truncate syscall paths perform their own append-only checks before calling notify_change(), so NFSD must make this decision against the locked size it is about to change. Split the write-count acquisition from the truncation permission check. Keep get_write_access() before the locked setattr work, then recheck whether the requested size is below i_size_read(inode) after inode_lock() has been acquired and before notify_change(ATTR_SIZE). This also avoids the plain unlocked inode->i_size load. The Linux kernel CVE team has assigned CVE-2026-89713 to this issue. Affected and fixed versions =========================== Issue introduced in 4.11 with commit 783112f7401ff449d979530209b3f6c2594fdb4e and fixed in 6.12.109 with commit 3afa17d93ba8c925f49370c816c6dae5112d8c24 Issue introduced in 4.11 with commit 783112f7401ff449d979530209b3f6c2594fdb4e and fixed in 6.18.50 with commit d8352da196349182e1afd5a93308256cddc0a97d Issue introduced in 4.11 with commit 783112f7401ff449d979530209b3f6c2594fdb4e and fixed in 7.2.4 with commit 44086254479035de42ca3d286ecf25521d4e6325 Issue introduced in 4.11 with commit 783112f7401ff449d979530209b3f6c2594fdb4e and fixed in 7.3-rc1 with commit b778e0e0a16759f22a70579c3cf8d254a40d4a7f Issue introduced in 3.2.89 with commit 604a3c407026d6162d15300478e63f901e435efc Issue introduced in 3.16.44 with commit cc4d5dc73841b98d33cdfb9822d70b0aac4beca5 Issue introduced in 4.4.53 with commit 3ee4f442e5b37a537297b812557b1163f96b5399 Issue introduced in 4.9.14 with commit a3c6cbc4eac4473ed5461d5faae2794d3e5c0e44 Issue introduced in 4.10.2 with commit 982898d7f97a35447403c3fcecc0d96c646ce101 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89713 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: fs/nfsd/vfs.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/3afa17d93ba8c925f49370c816c6dae5112d8c24 https://git.kernel.org/stable/c/d8352da196349182e1afd5a93308256cddc0a97d https://git.kernel.org/stable/c/44086254479035de42ca3d286ecf25521d4e6325 https://git.kernel.org/stable/c/b778e0e0a16759f22a70579c3cf8d254a40d4a7f