{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89697","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.750Z","datePublished":"2026-09-11T19:46:15.772Z","dateUpdated":"2026-09-14T12:02:04.273Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:02:04.273Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr()\n\nThe BOTH_TIME_SET branch calls fh_verify() early so setattr_prepare()\ncan inspect the dentry. This causes nfsd_setattr() to skip\nfh_want_write(), so notify_change() runs without a mount write\nreference.\n\nAdd the missing fh_want_write() call after the early fh_verify()."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","baseScore":9.1,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - The bug is in nfsd_proc_setattr(), the in-kernel NFSv2 SETATTR handler. A remote client reaches it by sending an NFSv2 SETATTR RPC over TCP/UDP port 2049 with both atime and mtime set, so no local access to the server is required.\nAC:L - Crafting SETATTR with ATTR_ATIME_SET|ATTR_MTIME_SET and equal timestamps deterministically takes the early fh_verify() path so nfsd_setattr() skips fh_want_write(). The attacker fully controls the RPC; no race or uninfluenced memory layout is required.\nPR:N - Default nfsd exports accept AUTH_SYS and AUTH_NULL with no cryptographic authentication, so the client asserts uid/gid. Any host permitted by the export list can issue SETATTR; this matches prior nfsd CNA scoring as PR:N.\nUI:N - The attacking NFS client issues the SETATTR RPC itself. No administrator or end-user action on the server is required.\nS:U - notify_change() without a mount write reference affects only the exported filesystem in the same kernel security authority. No VM, IOMMU, or sandbox boundary is crossed.\nC:N - The defect is a missing mnt_want_write()/sb_start_write() around notify_change() and commit_metadata(). It does not leak kernel memory, pointers, or file contents beyond ordinary authorized NFS access.\nI:H - nfsd_permission's read-only check does not cover freeze state, so SETATTR including ATTR_SIZE truncate, mode, and ownership updates proceeds on a frozen export and in a remount-ro race, letting a client mutate files and corrupt snapshots when writes should be blocked.\nA:H - Skipping freeze protection lets setattr run during fsfreeze, which can deadlock (inode_lock versus sb_start_write ordering), trigger filesystem withdraw/asserts such as GFS2 adding buffers while frozen, and hang or crash the nfsd thread."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfsd/nfsproc.c"],"versions":[{"version":"cc265089ce1b176dde963c74b53593446ee7f99a","lessThan":"3eec9d791968c177a4a8cda9af5c04f79dae09cb","status":"affected","versionType":"git"},{"version":"cc265089ce1b176dde963c74b53593446ee7f99a","lessThan":"9229d824b938f4fb0ea7a5dddade51735e6fe6f9","status":"affected","versionType":"git"},{"version":"cc265089ce1b176dde963c74b53593446ee7f99a","lessThan":"2150305134889fb2fc25228d35353bd2f6f29500","status":"affected","versionType":"git"},{"version":"cc265089ce1b176dde963c74b53593446ee7f99a","lessThan":"d823bf9285cdf4514873b85ab5a888878dd4e8f4","status":"affected","versionType":"git"},{"version":"cc265089ce1b176dde963c74b53593446ee7f99a","lessThan":"15ca3b64a69caa6194bed8f98a20ed90a11c11dd","status":"affected","versionType":"git"},{"version":"cc265089ce1b176dde963c74b53593446ee7f99a","lessThan":"533964d420d385e11b08dd4c56c66ef5dcccaf08","status":"affected","versionType":"git"},{"version":"cc265089ce1b176dde963c74b53593446ee7f99a","lessThan":"c4a409b86a92815181a8e9395c6bf1696ad19175","status":"affected","versionType":"git"},{"version":"cc265089ce1b176dde963c74b53593446ee7f99a","lessThan":"4e475be769aa9f7a2c1ce55a2b8592cfccacddcc","status":"affected","versionType":"git"},{"version":"1cb57d81cf20fe24b9e2e1daf57bfbdc24b77cd8","status":"affected","versionType":"git"},{"version":"3.18.46","lessThan":"3.19","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfsd/nfsproc.c"],"versions":[{"version":"4.2","status":"affected"},{"version":"0","lessThan":"4.2","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"7.3-rc1"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.18.46"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/3eec9d791968c177a4a8cda9af5c04f79dae09cb"},{"url":"https://git.kernel.org/stable/c/9229d824b938f4fb0ea7a5dddade51735e6fe6f9"},{"url":"https://git.kernel.org/stable/c/2150305134889fb2fc25228d35353bd2f6f29500"},{"url":"https://git.kernel.org/stable/c/d823bf9285cdf4514873b85ab5a888878dd4e8f4"},{"url":"https://git.kernel.org/stable/c/15ca3b64a69caa6194bed8f98a20ed90a11c11dd"},{"url":"https://git.kernel.org/stable/c/533964d420d385e11b08dd4c56c66ef5dcccaf08"},{"url":"https://git.kernel.org/stable/c/c4a409b86a92815181a8e9395c6bf1696ad19175"},{"url":"https://git.kernel.org/stable/c/4e475be769aa9f7a2c1ce55a2b8592cfccacddcc"}],"title":"nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr()","x_generator":{"engine":"bippy-1.2.0"}}}}