CRITICAL
nfsd Setattr TOCTOU
CVE-2026-89713
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
KernelScan AI5.6MEDIUM
01Description
In the Linux kernel, the following vulnerability has been resolved: NFSD: check truncate permission under inode lock nfsd_setattr() checks whether a size update needs NFSD_MAY_TRUNC before it takes inode_lock(). The comparison uses the file size sampled by that unlocked read, but the actual ATTR_SIZE update is applied later under inode_lock() by notify_change(). This leaves a TOCTOU window for append-only files. If a client sends a SETATTR that does not shrink the file at the time of the unlocked sample, a concurrent append can extend the file before nfsd_setattr() takes inode_lock(). notify_change() then applies a real truncation without the NFSD_MAY_TRUNC check that rejects IS_APPEND(inode). The VFS truncate syscall paths perform their own append-only checks before calling notify_change(), so NFSD must make this decision against the locked size it is about to change. Split the write-count acquisition from the truncation permission check. Keep get_write_access() before the locked setattr work, then recheck whether the requested size is below i_size_read(inode) after inode_lock() has been acquired and before notify_change(ATTR_SIZE). This also avoids the plain unlocked inode->i_size load.
02KernelScan AI Analysis
Risk summary
A TOCTOU race in nfsd_setattr() allows an NFS client to bypass append-only file truncation restrictions. By racing a SETATTR request with a concurrent append, the permission check sees a non-shrinking size while notify_change() later applies a real truncation. This can truncate append-only files without proper authorization.
Vulnerability analysis
The NFS server checks whether a client is allowed to truncate an append-only file before it locks the file for modification, while the actual size change happens later under that lock. Another operation can append to the file in between the permission check and the lock acquisition, causing the server to apply a truncation that should have been rejected. The fix moves the truncation permission check into the locked section so the decision uses the same size value that will actually be changed. Any NFS client that can send attribute-changing requests can reach this.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 3.2 | 3.2.89 | 3.3 | 3afa17d93ba8 |
| 3.16 | 3.16.44 | 3.17 | d8352da19634 |
| 4.4 | 4.4.53 | 4.5 | 440862544790 |
| 4.9 | 4.9.14 | 4.10 | b778e0e0a167 |
| 4.10 | 4.10.2 | 4.11 | — |
| 6.12 | — | 6.12.109 | — |
| 6.18 | — | 6.18.50 | — |
| 7.2 | — | 7.2.4 | — |
| mainline | — | 7.3-rc1 | — |