External risk intelligence

Linux Kernel NFS Out-of-Bounds Write and Memory Leak

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-89674

The vulnerability exists in the Linux kernel nfsd component, which handles NFS layout operations. While NFS services can be exposed, they are typically deployed within restricted internal networks, and direct exposure of NFS to the public internet is considered an uncommon and insecure configuration.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in the Linux kernel's NFS server component could allow unauthorized data access or modification. This issue stems from incorrect calculations when handling data buffer sizes, potentially leading to security risks. The primary concern is to confirm if this specific NFS functionality is in use and exposed.

  • Incorrect data buffer calculations create security risks.
  • Confirm if this NFS feature is actively used.
  • Assess relevance and potential exposure to your environment.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending specially crafted network requests to a system running a vulnerable Linux kernel. These requests target the NFS (Network File System) service, specifically the `nfsd4_ff_encode_layoutget` function. Errors in how the system calculates the size of data being sent over the network (XDR encoding) can be abused. This can lead to the kernel writing data outside of its intended memory space or leaking uninitialized kernel memory to the attacker, potentially resulting in code execution or information disclosure.

  • Network access required, no authentication.
  • Triggered by malformed NFS layoutget requests.
  • Memory corruption and sensitive data leakage.

Live Threat

Current exploitation, exposure, and threat context

The Linux kernel's NFS server (nfsd) component has a vulnerability in how it calculates XDR buffer sizes for layoutget operations. When supported, this could lead to an out-of-bounds write or the leaking of uninitialized kernel memory to an NFS client. This occurs due to incorrect handling of XDR padding, varying lengths for user and group IDs, and mismatches in length calculations for various fields. The most severe outcome, an out-of-bounds write, can happen with short strings and odd-sized file handles, potentially overwriting up to 5 bytes past the allocated buffer.

  • Kernel memory could be leaked to clients.
  • Errors in XDR buffer size calculations.
  • Client may receive stale or unexpected data.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the Linux kernel's NFS daemon (nfsd) could allow an unauthenticated attacker to cause an out-of-bounds write or leak uninitialized kernel memory. Real-world ownership would likely fall to the infrastructure or platform teams managing the Linux servers, with potential involvement from network and security teams for exposure assessment. The first practical step is to identify all NFS servers, determine their exposure, confirm the accountable owner, and then plan remediation based on the identified risk.

  • Ownership: Infrastructure/Platform teams manage NFS servers.
  • Verify: NFS server exposure and business criticality.
  • Action: Plan remediation with vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Linux kernel nfsd component?

The Linux kernel nfsd, or Network File System daemon, is a core subsystem that allows a Linux machine to act as a file server. It enables computers across a network to access and share files as if they were stored locally. This specific vulnerability involves the nfsd4_ff_encode_layoutget function, which manages complex data layout operations used when clients request information about how files are distributed across storage servers.

What is the vulnerability class for CVE-2026-89674?

This vulnerability is an improper input validation and memory safety issue. Specifically, it involves flawed XDR (eXternal Data Representation) buffer size calculations. These errors cause the system to miscalculate how much memory it needs to package data, leading to memory corruption or information exposure. In technical terms, it creates conditions for an out-of-bounds write, where the kernel overwrites memory outside of authorized boundaries, or an information leak of stale kernel memory.

How is this Linux kernel vulnerability triggered?

An attacker triggers this by sending malformed or specially crafted network requests to a system running an affected version of the nfsd component. The issue lies in the encoding of layout information, meaning it is specifically triggered by network-based interactions with NFS services. It is not triggered by standard, well-formed file operations; the bug requires specific combinations of string lengths and file handle sizes to manifest the memory calculation error.

Do I need to worry if my NFS server is internal?

According to Halo Surface Signal, this vulnerability is classified as 'Unlikely' to be exploited if your NFS services are restricted to internal networks. While the vulnerability technically allows for network-based attacks, NFS is traditionally meant for secure, private environments. If your NFS server is not directly exposed to the public internet, the practical risk is significantly lower, as the attacker would first need access to your internal network.

When should I take action for this NFS vulnerability?

You should prioritize this by first identifying all systems running NFS and confirming if they are reachable from untrusted networks. Since this is a kernel-level issue, remediation typically involves updating your Linux kernel via your distribution provider's security patches. Start by reviewing your server inventory, assessing the exposure of your NFS services, and coordinating with your infrastructure teams to schedule necessary kernel updates.

References