CVE-2026-89694

Source
https://cve.org/CVERecord?id=CVE-2026-89694
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89694.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89694
Downstream
Published
2026-09-11T19:46:13Z
Modified
2026-09-13T03:46:56Z
Summary
nfsd: check client ownership when cancelling a copy-notify stateid
Details

In the Linux kernel, the following vulnerability has been resolved:

nfsd: check client ownership when cancelling a copy-notify stateid

On the OFFLOAD_CANCEL path (clp != NULL), manage_cpntf_state() freed the target cpntf state without checking ownership. The lookup key st->si_opaque.so_id is allocated cyclically (guessable) and the embedded clientid is the fixed per-net nn->s2s_cp_cl_id, so any authenticated NFSv4.2 client could cancel and free another client's copy-notify stateid.

Compare the creating clientid recorded in state->cp_p_clid against the requesting client's cl_clientid and return nfserr_bad_stateid on a mismatch instead of freeing the entry.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89694.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ce0887ac96d35c7105090e166bb0807dc0a0e838
Fixed
b1eca07303594ca27f5dc360a6946bd7e1f5b04c
Fixed
b42dc26a14b4ad5d6daaada11ec4c70744141c25
Fixed
d801906165cb5cc250d5cbe44935594e170be3e2
Fixed
6bdbfab96e0cf25e5f57dac5c09dc1749751a4bf

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89694.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.6.0
Fixed
6.12.109
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.50
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89694.json"