{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89685","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.749Z","datePublished":"2026-09-11T19:46:07.116Z","dateUpdated":"2026-09-21T13:14:47.090Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-21T13:14:47.090Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: fix clock domain mismatch in clients_still_reclaiming()\n\nclients_still_reclaiming() computes a deadline from nn->boot_time\n(CLOCK_REALTIME, ~1.7 billion) but compares it against\nktime_get_boottime_seconds() (CLOCK_BOOTTIME, seconds since boot).\nThe comparison is always false — it would take ~54 years of uptime\nfor BOOTTIME to exceed the REALTIME-derived deadline.\n\nThis means any client can hold the server in grace indefinitely by\nsending CLAIM_PREVIOUS OPEN requests, blocking all non-reclaim\noperations for all other clients.\n\nAdd boot_time_bt (CLOCK_BOOTTIME) alongside the existing boot_time\nand use it for the deadline computation. boot_time (CLOCK_REALTIME)\nis preserved for its cl_boot clientid-nonce role."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - nfsd processes NFSv4 COMPOUND OPEN over TCP (typically port 2049). A remote peer reaches clients_still_reclaiming() by sending CLAIM_PREVIOUS OPEN or reclaim LOCK, which sets NFSD_NET_SOMEBODY_RECLAIMED and prevents grace from ending.\nAC:L - The attacker fully controls the reclaim OPEN/LOCK RPCs that keep NFSD_NET_SOMEBODY_RECLAIMED set; no race or memory layout is required. Grace always starts with nfsd, and the broken REALTIME-vs-BOOTTIME deadline never fires, so the attacker can extend it at will.\nPR:N - Default nfsd exports accept AUTH_SYS/AUTH_NULL with no credentials. An unauthenticated network peer that is or becomes a recorded NFSv4 client can send CLAIM_PREVIOUS OPEN; no server account or capability is required.\nUI:N - Exploitation takes only attacker-sent NFSv4 RPCs after nfsd starts; no victim user action such as mounting or opening a file is required.\nS:U - The impact stays in the same kernel nfsd/lockd grace state. This is a service denial on the NFS server, not a VM, IOMMU, or sandbox boundary crossing.\nC:N - The bug only miscompares grace deadlines and extends the grace period. It does not disclose kernel memory or file contents.\nI:N - No unauthorized modification of kernel or file data occurs. Other clients are blocked from new mutating operations, which is an availability effect rather than an integrity violation.\nA:H - Successful reclaim OPENs hold nfsd in grace indefinitely because the double-lease deadline never expires, so non-reclaim OPEN/REMOVE/RENAME/SETXATTR and lockd grace return NFS4ERR_GRACE and fully deny NFSv4 service to other clients."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfsd/netns.h","fs/nfsd/nfs4state.c"],"versions":[{"version":"20b7d86f29d39e8ae19bb29c24ffee70dc385ddf","lessThan":"e92e80c5b043108029bc729b30d12c37158fb9cb","status":"affected","versionType":"git"},{"version":"20b7d86f29d39e8ae19bb29c24ffee70dc385ddf","lessThan":"f9cec313efb2fd18d962aad738a4892bce806016","status":"affected","versionType":"git"},{"version":"20b7d86f29d39e8ae19bb29c24ffee70dc385ddf","lessThan":"9843649196221152b6e5d138a3ce859bdaae1d96","status":"affected","versionType":"git"},{"version":"20b7d86f29d39e8ae19bb29c24ffee70dc385ddf","lessThan":"09ea3eb9a518565f5bca386e81b993ed8825f5e8","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfsd/netns.h","fs/nfsd/nfs4state.c"],"versions":[{"version":"5.6","status":"affected"},{"version":"0","lessThan":"5.6","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/e92e80c5b043108029bc729b30d12c37158fb9cb"},{"url":"https://git.kernel.org/stable/c/f9cec313efb2fd18d962aad738a4892bce806016"},{"url":"https://git.kernel.org/stable/c/9843649196221152b6e5d138a3ce859bdaae1d96"},{"url":"https://git.kernel.org/stable/c/09ea3eb9a518565f5bca386e81b993ed8825f5e8"}],"title":"nfsd: fix clock domain mismatch in clients_still_reclaiming()","x_generator":{"engine":"bippy-1.2.0"}}}}