External risk intelligence

Linux Kernel NFSD Truncation Permission Check Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-89713

The vulnerability exists in the Linux kernel NFSD (NFS server) component. While NFS is frequently used within internal networks and is generally discouraged from being exposed directly to the public internet, it is plausibly reachable in certain deployments where storage services are exposed or misconfigured.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This security advisory addresses a flaw in the Linux kernel's network file system (NFS) server. The issue involves how the system checks permissions when modifying file sizes, potentially allowing unauthorized operations on append-only files. While the core technology is used internally, certain configurations could expose it to risk.

  • File size changes could be manipulated.
  • Confirm relevance to append-only file usage.
  • Assess potential impact on data integrity.

Attack Path

How an attacker could exploit the issue

An attacker could potentially exploit a race condition in how the Linux kernel's NFS server handles file truncation requests. By carefully timing operations, an attacker might trick the system into allowing a file to be truncated even if it's marked as append-only, potentially leading to data loss or corruption.

  • Entry condition: Attacker needs to access the NFS server.
  • Trigger point: Concurrent file append and truncate operations.
  • Resulting risk: Unauthorized file truncation and data corruption.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to bypass file size restrictions on append-only files, potentially leading to unauthorized data modification or denial of service when the NFS server is configured in specific ways.

  • File data integrity and availability.
  • Concurrent access with specific conditions.
  • Unintended file truncation or growth.

Operational Fix

Recommended remediation, mitigation, and detection steps

In real-world scenarios, the Linux kernel's NFS server (NFSD) component is typically managed by infrastructure or platform teams. The initial step for these teams is to locate all instances of the affected kernel version, confirm their network accessibility and business criticality, identify the accountable system owners, and then prioritize remediation based on risk.

  • Infrastructure/Platform teams own resolution.
  • Verify NFSD service reachability and criticality.
  • Plan and execute kernel updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Linux kernel NFSD component?

NFSD, or NFS Server Daemon, is a kernel-level service that enables a Linux machine to share its filesystems with other systems over a network. It acts as the backbone for remote file access, allowing users or servers to mount shared directories. This vulnerability specifically affects the code responsible for managing file attributes, such as size changes, within this network storage communication layer.

How does CVE-2026-89713 function as a vulnerability?

This is a Time-of-Check to Time-of-Use (TOCTOU) race condition. The kernel checks if a file modification is permitted before locking the file, then applies the change after locking it. An attacker can exploit this delay by triggering a concurrent operation—like appending data—after the initial check but before the lock is applied. This bypasses security checks meant to protect append-only files, potentially leading to unauthorized data truncation or corruption.

Do I need concurrent activity to trigger this flaw?

Yes, this bug requires a specific timing window where two operations interact. An attacker must perform a truncation request while the file is simultaneously being appended to. If the file is not configured as append-only, or if there is no concurrent activity attempting to extend the file during the request, the vulnerability does not manifest in the way described.

Is my system at risk according to Halo Surface Signal?

Halo Surface Signal identifies this as a potential risk because, while NFS is typically restricted to internal networks, it can be misconfigured or exposed to the public internet. If your NFS server is directly reachable from outside your protected network, your risk level increases. You should check if your NFS exports are inadvertently accessible to unauthorized networks.

How should I begin addressing this kernel vulnerability?

Start by identifying all servers in your environment running the affected Linux kernel versions that support the NFSD component. Once identified, evaluate the network accessibility and business importance of these systems. Since this is a kernel-level issue, the standard path for resolution is to coordinate with your infrastructure team to schedule and apply the necessary kernel updates provided by your distribution vendor.

References