---
cve: "CVE-2026-89665"
severity: "HIGH"
cvss: 8.2
epss: "27.2%"
vendor: "Linux"
kev: false
exploited: false
published: "2026-09-11 20:19:52"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-16T15:52:40+02:00"
---

# CVE-2026-89665

> 8.2 HIGH

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

nfsd: reject out-of-range useconds in NFSv2 SETATTR/CREATE

The NFSv2 sattr decoder converts the wire useconds to nanoseconds in
svcxdr_decode_sattr():

	iap->ia_atime.tv_nsec = tmp2 * NSEC_PER_USEC;

tmp2 is a u32 and NSEC_PER_USEC is 1000, so the product is computed in
unsigned long. On ILP32 that is 32 bits, and an out-of-range useconds
value such as 4294968 wraps to tv_nsec == 704. The corruption therefore
happens during decode, before any proc function can inspect the value,
and a later range check on tv_nsec would see an in-range result and
accept it. Rejecting in the decoder yields an RPC GARBAGE_ARGS reply.
NFSv2 defines no NFSERR_INVAL, so there is no NFS-level status to return
for a malformed time argument, and the check cannot move to the proc
function the way the v3/v4 nsec range checks do.

Guard the raw useconds before the multiplication and reject values
greater than 1000000. useconds == 1000000 is kept: it is the Sun
convention for "set to the current server time", and the in-tree Linux
NFSv2 client emits it in both the atime and the mtime field for a plain
touch / utimes(file, NULL) (see encode_sattr() and
xdr_encode_current_server_time() in fs/nfs/nfs2xdr.c). Rejecting 1000000
would turn that common operation into a hard decode failure for both
SETATTR and CREATE. 1000000 * NSEC_PER_USEC is 10^9, which does not wrap
on ILP32, so the Sun convention value passes through safely. Only
genuinely out-of-range values (> 1000000) are rejected. The atime and
mtime guards are therefore symmetric.

The decoder only applied the Sun convention in the mtime block, which
clears ATTR_ATIME_SET|ATTR_MTIME_SET when mtime useconds == 1000000. If a
client puts 1000000 in the atime field but not in the mtime field, the
atime block stored an out-of-range tv_nsec (10^9) and left ATTR_ATIME_SET
set, so the bogus value reached the filesystem. Apply the convention in
the atime block as well, clearing ATTR_ATIME_SET so the server uses its
current time and ignores the value. Only ATTR_ATIME_SET is cleared there.
The mtime block keeps its existing behavior, where 1000000 means "set
both atime and mtime to now".

[ cel: various tweaks, addenda, and clean-ups ]

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Keine | good |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Gering | warn |

## Patch verfügbar (OSV)

- Kernel ≥ 5.10.270
- Kernel ≥ 5.15.221
- Kernel ≥ 6.1.188
- Kernel ≥ 6.6.157
- Kernel ≥ 6.12.109
- Kernel ≥ 6.18.50
- Kernel ≥ 7.2.4

## Referenzen

- <https://git.kernel.org/stable/c/09a79d9ab35a39603c834e8f6333603292f9c816>
- <https://git.kernel.org/stable/c/1195483965a5f63d2dde18054ec7e50a23b9071c>
- <https://git.kernel.org/stable/c/1db456ffc22e045f49f7b9e62415a26b3f33f200>
- <https://git.kernel.org/stable/c/26709c8ffe73772eb69e68d553ac71d91228dccc>
- <https://git.kernel.org/stable/c/5296a2442d12d45d6eea7b4d3ec3ffecc1821cac>
- <https://git.kernel.org/stable/c/a937dd1aa2d92291fe0a1860d17e90d8f206cd22>
- <https://git.kernel.org/stable/c/ad02d095439f89cbd6629420c7e3ba476457b83b>
- <https://git.kernel.org/stable/c/cdc3299f7072777b09c9582a3b8b65bb163ddcf3>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-89665) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
