CVE-2026-89694

Summary

In the Linux kernel, the following vulnerability has been resolved:

nfsd: check client ownership when cancelling a copy-notify stateid

On the OFFLOAD_CANCEL path (clp != NULL), manage_cpntf_state() freed the target cpntf state without checking ownership. The lookup key st->si_opaque.so_id is allocated cyclically (guessable) and the embedded clientid is the fixed per-net nn->s2s_cp_cl_id, so any authenticated NFSv4.2 client could cancel and free another client's copy-notify stateid.

Compare the creating clientid recorded in state->cp_p_clid against the requesting client's cl_clientid and return nfserr_bad_stateid on a mismatch instead of freeing the entry.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxce0887ac96d35c7105090e166bb0807dc0a0e838 < b1eca07303594ca27f5dc360a6946bd7e1f5b04caffected
LinuxLinuxce0887ac96d35c7105090e166bb0807dc0a0e838 < b42dc26a14b4ad5d6daaada11ec4c70744141c25affected
LinuxLinuxce0887ac96d35c7105090e166bb0807dc0a0e838 < d801906165cb5cc250d5cbe44935594e170be3e2affected
LinuxLinuxce0887ac96d35c7105090e166bb0807dc0a0e838 < 6bdbfab96e0cf25e5f57dac5c09dc1749751a4bfaffected
LinuxLinux5.6affected
LinuxLinux0 < 5.6unaffected
LinuxLinux6.12.109 <= 6.12.*unaffected
LinuxLinux6.18.50 <= 6.18.*unaffected
LinuxLinux7.2.4 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References