Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-89713— NFSD: check truncate permission under inode lock

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: NFSD:在 inode 锁保护下检查截断权限 在获取 之前,会检查尺寸更新是否需要 权限。该检查所依据的文件大小是通过一次未加锁的读取操作获取的,而实际的 更新则是在后续持有 的情况下,由 应用的。 这为仅追加(append-only)文件留下了一个 TOCTOU(检查时间与使用时间) 窗口。如果在未加锁采样时客户端发送的 不会缩小文件,但在 获取 之前,可能有并发的追加操作延长了文件。此时 执行一次真正的截断操作,却未进行 检查来拒绝 。由于 VFS 中的 trunca

AI Predicted 5.5 Difficulty: Hard

Possible ATT&CK Techniques 2 AI

T1208 T1625

Affected Version Matrix 20

VendorProduct Version RangeStatus
Linux Linux 783112f7401ff449d979530209b3f6c2594fdb4e< 3afa17d93ba8c925f49370c816c6dae5112d8c24 affected
783112f7401ff449d979530209b3f6c2594fdb4e< d8352da196349182e1afd5a93308256cddc0a97d affected
783112f7401ff449d979530209b3f6c2594fdb4e< 44086254479035de42ca3d286ecf25521d4e6325 affected
783112f7401ff449d979530209b3f6c2594fdb4e< b778e0e0a16759f22a70579c3cf8d254a40d4a7f affected
604a3c407026d6162d15300478e63f901e435efc affected
cc4d5dc73841b98d33cdfb9822d70b0aac4beca5 affected
3ee4f442e5b37a537297b812557b1163f96b5399 affected
a3c6cbc4eac4473ed5461d5faae2794d3e5c0e44 affected
… +12 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-89713

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
NFSD: check truncate permission under inode lock
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: NFSD: check truncate permission under inode lock nfsd_setattr() checks whether a size update needs NFSD_MAY_TRUNC before it takes inode_lock(). The comparison uses the file size sampled by that unlocked read, but the actual ATTR_SIZE update is applied later under inode_lock() by notify_change(). This leaves a TOCTOU window for append-only files. If a client sends a SETATTR that does not shrink the file at the time of the unlocked sample, a concurrent append can extend the file before nfsd_setattr() takes inode_lock(). notify_change() then applies a real truncation without the NFSD_MAY_TRUNC check that rejects IS_APPEND(inode). The VFS truncate syscall paths perform their own append-only checks before calling notify_change(), so NFSD must make this decision against the locked size it is about to change. Split the write-count acquisition from the truncation permission check. Keep get_write_access() before the locked setattr work, then recheck whether the requested size is below i_size_read(inode) after inode_lock() has been acquired and before notify_change(ATTR_SIZE). This also avoids the plain unlocked inode->i_size load.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 783112f7401ff449d979530209b3f6c2594fdb4e ~ 3afa17d93ba8c925f49370c816c6dae5112d8c24 -
Linux Linux 4.11 -

II. Public POCs for CVE-2026-89713

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-89713

登录查看更多情报信息。

Patches & Fixes for CVE-2026-89713 (4)

Same Patch Batch · Linux · 2026-09-11 · 431 CVEs total

CVE-2026-89491 ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin()
CVE-2026-89477 sctp: fix NULL deref on untransmitted RECONF completion
CVE-2026-89478 sctp: drop a chunk if its transport was removed
CVE-2026-89479 sctp: stop processing a packet once its association is deleted
CVE-2026-89480 nvme-tcp: reject a read that transferred too few bytes
CVE-2026-89482 nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone
CVE-2026-89481 nvme-tcp: fix host memory disclosure on R2T for a read command
CVE-2026-89483 nvme: zero the discard fallback page
CVE-2026-89484 lockd: fix NULL dereference on lockowner allocation failure
CVE-2026-89485 lockd: pin next file across nlm_inspect_file lock-drop
CVE-2026-89486 ipmi: Fix use-after-free of cmd_rcvr in _ipmi_destroy_user()
CVE-2026-89487 openvswitch: only skb_tx_error() a packet we are about to drop
CVE-2026-89488 openvswitch: Fix CT limit teardown use-after-free
CVE-2026-89489 openrisc: fix arbitrary kernel memory access via or1k_atomic syscall
CVE-2026-89500 ring-buffer: Make cpu_buffer::free_page a buffer_data_read_page
CVE-2026-89497 orangefs: skip leading spaces before parsing client debug masks
CVE-2026-89498 orangefs: fix double-free of trailer_buf on readdir copy failure
CVE-2026-89499 ring-buffer: Stop remote reader update when page swap fails
CVE-2026-89496 ocfs2: always run deallocs on copy-on-write completion
CVE-2026-89501 ring-buffer: Hold cpu_buffer::lock when resizing a subbuf

Showing top 20 of 431 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-89713

No comments yet


Leave a comment