CVE-2026-89669

Source
https://cve.org/CVERecord?id=CVE-2026-89669
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89669.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89669
Downstream
Published
2026-09-11T19:45:55Z
Modified
2026-09-13T03:47:20Z
Summary
nfsd: initialize copy-notify stateid before publishing it
Details

In the Linux kernel, the following vulnerability has been resolved:

nfsd: initialize copy-notify stateid before publishing it

nfsd4_copy_notify() finished initializing the cpntf state after nfs4_alloc_init_cpntf_state() had already linked it into the s2s_cp_stateids IDR and the parent's sc_cp_list, with cs_count == 1 (the membership reference) and none held for the caller. A racing OFFLOAD_CANCEL (crafted cl_id == nn->s2s_cp_cl_id plus the guessable so_id) could reach manage_cpntf_state() and free the entry, turning the caller's subsequent cpn_cnr_stateid read and cp_p_stateid/cp_p_clid writes into use-after-free. The owning clientid was also only recorded after publication, so it could not gate an ownership check in that window.

Record cp_p_stateid and cp_p_clid inside nfs4_alloc_init_cpntf_state() before nfs4_init_cp_state() publishes the entry, and return it with an extra reference. The caller reads the stateid under that reference and drops it with nfs4_put_cpntf_state(); on a late error the laundromat reaps the entry.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89669.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
624322f1adc58acd0b69f77a6ddc764207e97241
Fixed
e08a3dcaca0505f861e344a387f37f94d95dbdc2
Fixed
a4d7fedcaaf33e60a01e53eafca9041ef966212f
Fixed
4cdef96892f4fa6e70c405b6e8f2fd6972f3b64b
Fixed
129643893b79f8a3c6b72045f933fbab5ee424ca

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89669.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.6.0
Fixed
6.12.109
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.50
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89669.json"