| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-89681 | nfsd: fix layout fence worker double-reference race | Linux | Linux | Critical | 9.8 | 2026-09-11 19:46:04 | Deep Dive |
| CVE-2026-89677 | nfsd: fix possible fh_compose of wrong dentry in nfsd4_create_file() | Linux | Linux | Critical | 9.8 | 2026-09-11 19:46:01 | Deep Dive |
| CVE-2026-89675 | nfsd: fix UAF in async copy cancel and shutdown | Linux | Linux | Critical | 9.8 | 2026-09-11 19:46:00 | Deep Dive |
| CVE-2026-89676 | nfsd: fix stale s2s_cp_stateids IDR entry for async COPY | Linux | Linux | Critical | 9.8 | 2026-09-11 19:46:00 | Deep Dive |
| CVE-2026-89674 | nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget | Linux | Linux | Critical | 9.8 | 2026-09-11 19:45:59 | Deep Dive |
| CVE-2026-89671 | nfsd: gate nfs3 setacl by argp->mask | Linux | Linux | Critical | 9.1 | 2026-09-11 19:45:57 | Deep Dive |
| CVE-2026-89672 | nfsd: gate nfs2 setacl by argp->mask | Linux | Linux | Critical | 9.1 | 2026-09-11 19:45:57 | Deep Dive |
| CVE-2026-89669 | nfsd: initialize copy-notify stateid before publishing it | Linux | Linux | Critical | 9.8 | 2026-09-11 19:45:55 | Deep Dive |
| CVE-2026-89662 | NFSD: Prevent lock owner use-after-free during client teardown | Linux | Linux | Critical | 9.8 | 2026-09-11 19:45:50 | Deep Dive |
| CVE-2026-89660 | NFSD: Prevent client use-after-free during admin state revocation | Linux | Linux | Critical | 9.8 | 2026-09-11 19:45:48 | Deep Dive |
| CVE-2026-89659 | NFSD: Prevent client use-after-free during delegation revoke | Linux | Linux | Critical | 9.8 | 2026-09-11 19:45:48 | Deep Dive |
| CVE-2026-89658 | NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup | Linux | Linux | Critical | 9.8 | 2026-09-11 19:45:47 | Deep Dive |
| CVE-2026-89656 | libceph: reject buckets with mismatched CRUSH ids | Linux | Linux | Critical | 9.8 | 2026-09-11 19:45:45 | Deep Dive |
| CVE-2026-89655 | ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock | Linux | Linux | Critical | 9.8 | 2026-09-11 19:45:45 | Deep Dive |
| CVE-2026-89654 | ceph: fix UAF in check_new_map() on session freed during unlock | Linux | Linux | Critical | 9.8 | 2026-09-11 19:45:44 | Deep Dive |
| CVE-2026-89653 | ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode | Linux | Linux | Critical | 9.8 | 2026-09-11 19:45:43 | Deep Dive |
| CVE-2026-89652 | ceph: bound copied dentry name length in NFS export get_name | Linux | Linux | Critical | 9.8 | 2026-09-11 19:45:42 | Deep Dive |
| CVE-2026-89651 | ceph: bound MDSCapAuth path and fs_name decode in handle_session() | Linux | Linux | Critical | 9.8 | 2026-09-11 19:45:42 | Deep Dive |
| CVE-2026-89650 | ceph: bound num_export_targets array for mds info v2/v3 | Linux | Linux | Critical | 9.1 | 2026-09-11 19:45:41 | Deep Dive |
| CVE-2026-89649 | ceph: bound xattr value length in __build_xattrs() | Linux | Linux | Critical | 9.1 | 2026-09-11 19:45:40 | Deep Dive |