CVE-2026-89694
Received Received - Intake

Linux Kernel NFSv4.2 Stateid Ownership Bypass

Vulnerability report for CVE-2026-89694, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: nfsd: check client ownership when cancelling a copy-notify stateid On the OFFLOAD_CANCEL path (clp != NULL), manage_cpntf_state() freed the target cpntf state without checking ownership. The lookup key st->si_opaque.so_id is allocated cyclically (guessable) and the embedded clientid is the fixed per-net nn->s2s_cp_cl_id, so any authenticated NFSv4.2 client could cancel and free another client's copy-notify stateid. Compare the creating clientid recorded in state->cp_p_clid against the requesting client's cl_clientid and return nfserr_bad_stateid on a mismatch instead of freeing the entry.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves improper handling of NFSv4.2 copy-notify stateids. An authenticated client could cancel and free another client's stateid due to a guessable lookup key and lack of ownership verification. The fix ensures the requesting client's ID is checked against the state's creator before cancellation.

Detection Guidance

This vulnerability affects NFSv4.2 clients using OFFLOAD_CANCEL operations. Detection requires checking kernel logs for unauthorized stateid cancellations or monitoring NFS server operations for unexpected client interactions. No specific commands are provided in the context.

Impact Analysis

An attacker with NFSv4.2 access could disrupt another client's file operations by cancelling their copy-notify stateid, potentially causing data corruption or denial of service for legitimate users.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it pertains to a Linux kernel issue in NFSv4.2 client operations. Compliance implications would depend on how the affected system is used and whether unauthorized access to stateids could lead to data exposure or integrity issues.

Mitigation Strategies

Apply the Linux kernel patch that introduces ownership checks for stateid cancellations. Update to a patched kernel version immediately. Monitor NFS server logs for suspicious activity post-update.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89694. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart