{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.2.6-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  nfsd: fix partial-write detection in nfsd_direct_write  nfsd_direct_write() walks a list of write segments and, after each vfs_iocb_iter_write(), tries to detect a short write so the loop can stop before placing the next segment at a wrong file offset:      host_err = vfs_iocb_iter_write(file, kiocb, \u0026segments[i].iter);     if (host_err \u003c 0)             return host_err;     *cnt += host_err;     if (host_err \u003c segments[i].iter.count)             break;\t/* partial write */  vfs_iocb_iter_write() runs the iter through -\u003ewrite_iter(), which advances the iter by the number of bytes written. By the time the check runs, segments[i].iter.count is the residual, not the original request length:      before write_iter: iter.count == original_len     after  write_iter: iter.count == original_len - host_err  The condition then reduces to host_err \u003c original_len - host_err, so the break fires only when less than half of the segment was written. Any short write completing between 50% and 99% of the segment slips through; the loop advances to the next segment with kiocb-\u003eki_pos only bumped by the short amount, writing the next segment's payload at the wrong offset and over-reporting *cnt to the NFS client.  Snapshot the segment's byte count before the write and compare host_err against that snapshot so any short write breaks the loop.",
  "id": "DEBIAN-CVE-2026-89678",
  "modified": "2026-09-23T03:47:30.363094550Z",
  "published": "2026-09-11T20:19:54.523Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-89678"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-89678"
  ]
}