๐Ÿ” CVE Alert

CVE-2026-89669

CRITICAL 9.8

nfsd: initialize copy-notify stateid before publishing it

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: nfsd: initialize copy-notify stateid before publishing it nfsd4_copy_notify() finished initializing the cpntf state after nfs4_alloc_init_cpntf_state() had already linked it into the s2s_cp_stateids IDR and the parent's sc_cp_list, with cs_count == 1 (the membership reference) and none held for the caller. A racing OFFLOAD_CANCEL (crafted cl_id == nn->s2s_cp_cl_id plus the guessable so_id) could reach manage_cpntf_state() and free the entry, turning the caller's subsequent cpn_cnr_stateid read and cp_p_stateid/cp_p_clid writes into use-after-free. The owning clientid was also only recorded after publication, so it could not gate an ownership check in that window. Record cp_p_stateid and cp_p_clid inside nfs4_alloc_init_cpntf_state() before nfs4_init_cp_state() publishes the entry, and return it with an extra reference. The caller reads the stateid under that reference and drops it with nfs4_put_cpntf_state(); on a late error the laundromat reaps the entry.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new critical vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
624322f1adc58acd0b69f77a6ddc764207e97241 < 863b6e995665472f2af5be2436a874ab6a9e5ac6 624322f1adc58acd0b69f77a6ddc764207e97241 < d18d36395d973ef7372c8e6724970585f75b5c0b 624322f1adc58acd0b69f77a6ddc764207e97241 < 4415a692346a39fdb647cbd717eda510159aaf55 624322f1adc58acd0b69f77a6ddc764207e97241 < 9caad13b7cfe9ccb90cc405ac77335800e086595 624322f1adc58acd0b69f77a6ddc764207e97241 < e08a3dcaca0505f861e344a387f37f94d95dbdc2 624322f1adc58acd0b69f77a6ddc764207e97241 < a4d7fedcaaf33e60a01e53eafca9041ef966212f 624322f1adc58acd0b69f77a6ddc764207e97241 < 4cdef96892f4fa6e70c405b6e8f2fd6972f3b64b 624322f1adc58acd0b69f77a6ddc764207e97241 < 129643893b79f8a3c6b72045f933fbab5ee424ca
Linux / Linux
5.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/863b6e995665472f2af5be2436a874ab6a9e5ac6 git.kernel.org: https://git.kernel.org/stable/c/d18d36395d973ef7372c8e6724970585f75b5c0b git.kernel.org: https://git.kernel.org/stable/c/4415a692346a39fdb647cbd717eda510159aaf55 git.kernel.org: https://git.kernel.org/stable/c/9caad13b7cfe9ccb90cc405ac77335800e086595 git.kernel.org: https://git.kernel.org/stable/c/e08a3dcaca0505f861e344a387f37f94d95dbdc2 git.kernel.org: https://git.kernel.org/stable/c/a4d7fedcaaf33e60a01e53eafca9041ef966212f git.kernel.org: https://git.kernel.org/stable/c/4cdef96892f4fa6e70c405b6e8f2fd6972f3b64b git.kernel.org: https://git.kernel.org/stable/c/129643893b79f8a3c6b72045f933fbab5ee424ca