Kernel-level NFS server bug in widely deployed Linux; can cause memory leaks or corruption and affect many deployments.
CVE-2026-89674
Linux NFS server XDR length bug allows kernel memory leak or OOB write
Is CVE-2026-89674 being exploited?
Not confirmed. CVE-2026-89674 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.52% probability of exploitation in the next 30 days.
How severe is CVE-2026-89674?
CVE-2026-89674 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-89674?
Yes. A fix has been recorded for CVE-2026-89674. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-89674 affect?
CVE-2026-89674 affects Linux kernel (nfsd NFSv4 server). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-89674?
Install kernel updates with the fix; restart NFS server; restrict untrusted NFS clients
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Remote NFS client can trigger out-of-bounds write or leak uninitialized kernel memory, risking kernel crash, info disclosure, or privilege escalation.
Immediate action required
- affected>= 9b9960a0ca4773e21c4b153ed355583946346b25 and < e7d9d23ecd9172f05b09bb678ff22db8e361c428
- affected>= 9b9960a0ca4773e21c4b153ed355583946346b25 and < 0380129b1373c437eb35401a174671c8888f4b80
- affected>= 9b9960a0ca4773e21c4b153ed355583946346b25 and < c81cef6a805dec266c10fc4f83c93d6fcf1a2b43
- affected>= 9b9960a0ca4773e21c4b153ed355583946346b25 and < f9868174af49d207fbaf0c5e055d088a983684af
- affected4.8
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.