# CVE-2026-89691

## Summary

- **CVE ID:** CVE-2026-89691
- **Severity:** HIGH
- **CVSS Score:** 7.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H)
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 13, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

nfsd: clear opcnt on compound arg release to prevent OOB read

nfsd4_release_compoundargs() resets args->ops to the inline iops[8]
array when the dynamically-allocated ops buffer is freed, but leaves
args->opcnt at its original value (which can be up to 200 for NFSv4.1+
compounds).

If rq_status_counter is stuck at an odd value (which can happen when
nfsd_dispatch() hits an error path after setting it odd), the RPC
status dumpit handler reads min(opcnt, 16) entries from args->ops[].
Since iops only has 8 elements and is the last field in struct
nfsd4_compoundargs, reading indices 8-15 accesses adjacent slab memory
and leaks it to userspace via netlink.

Zero opcnt unconditionally in nfsd4_release_compoundargs() so stale
compound metadata is never exposed through the status interface.

[ cel: Remove the kvfree_rcu_mightsleep() sleep from the exposure window ]

## Affected Products

- Linux — Linux (bd9d6a3efa9709e653aafbeb859289feccb8e70c)
- Linux — Linux (6.7)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)

## References

- [CNA](https://git.kernel.org/stable/c/58bcdfb2b2e412088839ae740b1a95154dc0b8d0)
- [CNA](https://git.kernel.org/stable/c/e879148867bd4c4cac42e063ffaffa187dddc6fe)
- [CNA](https://git.kernel.org/stable/c/c1a4f7b1848f95302df598217e1c7a1410c2d0c5)
- [CNA](https://git.kernel.org/stable/c/ae4c38555e81563b8dc5eae55ffd70f0ea97aa5a)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.13%
- **EPSS Percentile:** 2.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._