PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-89695 Linux CVE debrief

A vulnerability in the Linux kernel's nfsd has been resolved, where an attacker could have caused unbounded CPU usage in the server's compound processing path by sending a specially crafted POSIX ACL count. The fix involves capping the decoded POSIX ACL count to prevent O(n^2) bubble sort operations. This vulnerability could allow an attacker to cause high CPU usage, potentially leading to denial-of-service conditions. Linux kernel developers, nfsd administrators, and security teams should assess exposure and prioritize patching.

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-11
Original CVE updated
2026-09-11
Advisory published
2026-09-11
Advisory updated
2026-09-11

Who should care

Linux kernel developers and maintainers, nfsd service administrators, and security teams responsible for Linux kernel patch management should assess exposure and prioritize patching. These teams should review system configurations, kernel versions, and nfsd service exposure to determine the extent of potential impact and implement necessary mitigations.

Why it matters

This vulnerability in the Linux kernel's nfsd could allow an attacker to cause high CPU usage, potentially leading to denial-of-service conditions. Linux kernel developers, nfsd administrators, and security teams should assess exposure and prioritize patching.

  • Potential for CPU resource exhaustion due to unbounded sort operations.
  • Need for patching to prevent potential denial-of-service (DoS) attacks.
  • Importance of monitoring system resources for nfsd service anomalies.

Technical summary

The Linux kernel's nfsd has a vulnerability where an attacker could cause unbounded CPU usage by sending a specially crafted POSIX ACL count. The fix involves capping the decoded POSIX ACL count to prevent O(n^2) bubble sort operations. This vulnerability could allow an attacker to cause high CPU usage, potentially leading to denial-of-service conditions. The fix is included in specific kernel commits and requires review of system configurations and kernel versions to determine exposure and prioritize patching. Defenders should assess exposure based on the provided CVE and NVD information.

Defensive priority

Medium

Recommended defensive actions

  • Review and apply the provided kernel patches to prevent potential CPU usage issues.
  • Monitor system resources for nfsd service to detect potential anomalies.
  • Consider implementing rate limiting for incoming NFS requests to mitigate potential attacks.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but the scope of affected systems and versions is not explicitly stated. The fix is included in specific kernel commits. Further review of system configurations, kernel versions, and nfsd service exposure is necessary to determine the extent of potential impact. Defenders should verify system patch levels and assess exposure based on the provided CVE and NVD information.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-89695 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-89695

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-89695 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-89695

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/4bc1108e876153a2dd6d874052b99182c3603135

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/ea14d71d6ecb925673761bcf79f781f7dc9042cc

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.