Database/Control plane, storage & DevOps
Linux SUNRPC (xdr_buf_to_bvec, nfsd write path): xdr_buf_to_bvec stores a bio_vec before checking the slot is in range
Impact
xdr_buf_to_bvec stores a bio_vec before checking the slot is in range, so a client-controlled RPC payload size drives an out-of-bounds write into adjacent kernel slab memory on the NFS server. The overflowing values come straight from the client, which makes this a remote kernel memory corruption on the shared file server.
Who can reach it
Any NFS client that can send writes to the server - i.e. any tenant compute node with the export mounted.
What to do
Update the NFS server kernel to one with the bound-check-before-store fix in SUNRPC and reboot. This is in the write path, so there is no useful config workaround short of making the export read-only.
References
Related entries
- Linux VXLAN driver (transmit-path header pulls): `vxlan_xmit()`, `arp_reduce()` and `vxlan_mdb_entry_skb_get()`CVE-2026-74474 · Linux VXLAN driver (transmit-path header pulls)Critical
- Airflow Keycloak provider: credentials of any confidential client in the realm log into AirflowCVE-2026-76187 · Apache Airflow Keycloak provider (unauthenticated token endpoint, client-credentials grant)Critical
- Airflow FAB provider: password reset fails to evict existing sessions, so a stolen cookie keeps workingCVE-2026-82311 · Apache Airflow FAB provider (password reset does not delete database-backed sessions)Critical
- Linux nfsd: async server-side COPY registers a stateid pointing into a reused request bufferCVE-2026-89676 · Linux NFS server (nfsd, s2s_cp_stateids IDR for async COPY)Critical
- Linux nfsd: filehandle composed from a stale dentry when dentry_create returns a different dentryCVE-2026-89677 · Linux NFS server (nfsd4_create_file, fh_compose on the wrong dentry)Critical
- Linux nfsd: pNFS layout fence worker takes a duplicate reference and leaks the layout stateidCVE-2026-89681 · Linux NFS server (nfsd pNFS layout fence worker, lm_breaker_timedout)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.