VYPR
AI Brief2026-09-14· generated Sep 14, 2026

What you need to know today.

Linux kernel NFS flaws, sngrep buffer overflows, and Tonec IDM access issues disclosed.

Multiple vulnerabilities have been discovered in the Linux kernel's NFS (Network File System) server (nfsd) component, collectively addressed in recent updates. These flaws, including several critical issues with CVSS scores of 9.8, primarily involve use-after-free vulnerabilities, race conditions, and improper handling of stateids and client data during session teardown, delegation revocation, and copy operations. Specific CVEs include CVE-2026-89712, CVE-2026-89708, CVE-2026-89703, CVE-2026-89702, CVE-2026-89689, CVE-2026-89688, CVE-2026-89686, CVE-2026-89681, CVE-2026-89677, CVE-2026-89676, CVE-2026-89675, CVE-2026-89674, CVE-2026-89669, CVE-2026-89662, CVE-2026-89660, CVE-2026-89659, and CVE-2026-89658. These issues could lead to system instability or potential security compromises in environments utilizing NFSv4. The Linux kernel has released patches to mitigate these risks.

A critical vulnerability (CVE-2026-90558) has been identified in sngrep through version 1.8.4, stemming from stack buffer overflows within its SIP attribute formatting routines. This vulnerability is triggered when header values exceed the 255-byte buffer limit, allowing attackers to craft malicious SIP packets with oversized Call-ID or X-Call-ID headers to exploit the overflow. Successful exploitation could lead to denial-of-service or potentially code execution. Users are advised to update to a patched version of sngrep.

A high-severity vulnerability (CVE-2026-90493) has been found in Tonec Internet Download Manager up to version 6.42 Build 63 on Windows. The flaw resides in an unknown function within the idmwfp.sys kernel driver component, potentially allowing for improper access controls. This could enable unauthorized access or manipulation of system resources. Users should update to the latest available version to address this vulnerability.

In the Ceph distributed storage system, a vulnerability (CVE-2026-89656) in the libceph component has been disclosed. The issue lies in the rejection of buckets with mismatched CRUSH (Controlled Replication Under Scalable Hashing) IDs during the decoding process. This could lead to inconsistencies or failures in data placement and retrieval within Ceph clusters. Patches are available for affected versions.

Synthesized by Vypr AI