{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89684","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.748Z","datePublished":"2026-09-11T19:46:06.374Z","dateUpdated":"2026-09-14T12:02:01.056Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:02:01.056Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: fix cpntf publish race in nfs4_init_cp_state\n\nnfs4_alloc_init_cpntf_state() published the new cpntf entry into the\ns2s_cp_stateids IDR (with cs_type set) in one s2s_cp_lock section, then\ntook the lock again to list_add() it onto p_stid->sc_cp_list. In the gap\nthe entry is reachable by so_id but cp_list is still {NULL,NULL} from\nkzalloc. A racing OFFLOAD_CANCEL (so_id is echoed to the client as\ncnr_stateid, so any NFSv4.2 client can drive it) reaches\nmanage_cpntf_state() -> _free_cpntf_state_locked() and does list_del() on\nthe zeroed list_head, oopsing the server.\n\nFold the cs_type assignment and the list_add() into the same critical\nsection as idr_alloc_cyclic(), so a concurrent lookup either misses the\nentry or sees a fully linked cp_list. INIT_LIST_HEAD() the entry after\nallocation and switch _free_cpntf_state_locked() to list_del_init() so a\nstale unlink is a no-op. nfs4_init_copy_state() passes NULL p_stid and\nskips the list_add, preserving NFS4_COPY_STID semantics."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - The flaw is in nfsd NFSv4.2 COPY_NOTIFY/OFFLOAD_CANCEL (nfsd4_copy_notify, nfs4_alloc_init_cpntf_state, manage_cpntf_state). Compounds reach nfsd4_proc_compound via svc_process on TCP/2049, so a remote NFS client triggers the published cpntf IDR entry over the network.\nAC:L - The attacker drives both sides: COPY_NOTIFY publishes the cpntf into s2s_cp_stateids while a concurrent OFFLOAD_CANCEL uses the leaked s2s_cp_cl_id and cyclic so_id to list_del the still-zeroed cp_list. The window is retryable on multiple session slots with no victim-controlled state.\nPR:N - Default AUTH_SYS/AUTH_NULL nfsd exports do no cryptographic authentication. Any host allowed by the export ACL can EXCHANGE_ID/CREATE_SESSION, OPEN a readable file, and issue COPY_NOTIFY and OFFLOAD_CANCEL; no local account or capability on the NFS server is required.\nUI:N - The attacking NFS client sends COPY_NOTIFY and the concurrent OFFLOAD_CANCEL itself; no victim user or administrator action on the NFS server is required at attack time.\nS:U - list_del of the uninitialized cp_list oopses an nfsd worker in the host kernel copy-notify tables. Impact stays in that kernel security authority and does not cross a VM, IOMMU, or sandbox boundary.\nC:N - The race is list_del on a kzalloc'd nfs4_cpntf_state.cp_list still {NULL,NULL}, a NULL-pointer dereference in __list_del. It oopses without reading kernel memory or providing an information-disclosure primitive.\nI:N - The only write is next->prev/prev->next through NULL list pointers from kzalloc; a remote NFS client cannot map the NULL page, so this is not a kernel write or control-flow hijack primitive.\nA:H - list_del on the zeroed list_head oopses or panics the nfsd thread (and can leak s2s_cp_lock). The attacker can repeat the concurrent COMPOUND sequence to deny NFS service and take down the server."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfsd/nfs4state.c"],"versions":[{"version":"624322f1adc58acd0b69f77a6ddc764207e97241","lessThan":"63e18fc65587fd3f7b4c6d70e96d32fc41d82ba3","status":"affected","versionType":"git"},{"version":"624322f1adc58acd0b69f77a6ddc764207e97241","lessThan":"6ac469a274e3c7d87fc46ba46d83b95009680407","status":"affected","versionType":"git"},{"version":"624322f1adc58acd0b69f77a6ddc764207e97241","lessThan":"8eeca993357a0bc35aaefebfd7462ac7b0a21d9a","status":"affected","versionType":"git"},{"version":"624322f1adc58acd0b69f77a6ddc764207e97241","lessThan":"bfeac42d9074e539bacd1898dd8c14b7f5776620","status":"affected","versionType":"git"},{"version":"624322f1adc58acd0b69f77a6ddc764207e97241","lessThan":"21d6c5957f5ca97d7352e60f55ea412beb9419f5","status":"affected","versionType":"git"},{"version":"624322f1adc58acd0b69f77a6ddc764207e97241","lessThan":"a631a26a8777bb235eabd478bbbaf26a4db750bf","status":"affected","versionType":"git"},{"version":"624322f1adc58acd0b69f77a6ddc764207e97241","lessThan":"c7270f62e7a05a2ee68aa2b74262b658a14463bd","status":"affected","versionType":"git"},{"version":"624322f1adc58acd0b69f77a6ddc764207e97241","lessThan":"be3a5c1d857b0dcbc11796cea603ef25834f75b2","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfsd/nfs4state.c"],"versions":[{"version":"5.6","status":"affected"},{"version":"0","lessThan":"5.6","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/63e18fc65587fd3f7b4c6d70e96d32fc41d82ba3"},{"url":"https://git.kernel.org/stable/c/6ac469a274e3c7d87fc46ba46d83b95009680407"},{"url":"https://git.kernel.org/stable/c/8eeca993357a0bc35aaefebfd7462ac7b0a21d9a"},{"url":"https://git.kernel.org/stable/c/bfeac42d9074e539bacd1898dd8c14b7f5776620"},{"url":"https://git.kernel.org/stable/c/21d6c5957f5ca97d7352e60f55ea412beb9419f5"},{"url":"https://git.kernel.org/stable/c/a631a26a8777bb235eabd478bbbaf26a4db750bf"},{"url":"https://git.kernel.org/stable/c/c7270f62e7a05a2ee68aa2b74262b658a14463bd"},{"url":"https://git.kernel.org/stable/c/be3a5c1d857b0dcbc11796cea603ef25834f75b2"}],"title":"nfsd: fix cpntf publish race in nfs4_init_cp_state","x_generator":{"engine":"bippy-1.2.0"}}}}