CVE-2026-89699 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 nfsd nfsd4_decode_create cr_datalen out-of-bounds write

SecurityVulns

A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. It has been rated as critical. Affected by this issue is the function nfsd4_decode_create of the component nfsd. This manipulation of the argument cr_datalen causes out-of-bounds write.

This vulnerability is registered as CVE-2026-89699. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More