CVE-2026-89673

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo nfsd4_ff_encode_getdeviceinfo() computes the da_addr_body reservation as 16 + netid_len + addr_len, but the subsequent xdr_encode_opaque() calls emit 8 + round_up(netid_len, 4) + round_up(addr_len, 4) bytes. The mismatch means the declared da_addr_body length exceeds the actual encoded data by 2-8 bytes on every flexfile GETDEVICEINFO reply, leaking stale reply-page content to the client and mis-aligning the subsequent version list decode. Use xdr_align_size() for each string length to match what xdr_encode_opaque() actually writes.

Package Linux Kernel
Published 2026-09-11
Last modified 2026-09-14
Patch available
Yes

Affected versions

Linux kernel versions 6.4.16 and later are affected. Fixed in 6.6.157 and their respective stable series.

Affected from
≥ 6.4.16
Fixed in
✓ 6.6.157 6.6.x

Frequently asked questions

  • What is CVE-2026-89673?

    CVE-2026-89673 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 6.4.16 onward and has been patched in 6.6.157. CVE-2026-89673 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-89673?

    Yes. CVE-2026-89673 has been patched. Fixed versions include 6.6.157. If you are running Linux kernel 6.4.16 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-89673 actively exploited?

    No. CVE-2026-89673 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.