{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89704","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.750Z","datePublished":"2026-09-11T19:46:21.039Z","dateUpdated":"2026-09-14T12:02:06.394Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:02:06.394Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: sample writeback error cursor before async COPY loop\n\n_nfsd_copy_file_range() samples dst->f_wb_err into \"since\"\nafter the copy loop, then uses it to detect writeback errors\nvia filemap_check_wb_err() once vfs_fsync_range() returns.\nBecause the nfsd_file cache reuses a single struct file\nacross requests targeting the same inode, a concurrent\nCOMMIT or stable WRITE on dst advances dst->f_wb_err to the\ncurrent mapping->wb_err via file_check_and_advance_wb_err()\nduring its own vfs_fsync_range(). If that advancement lands\nbetween the writeback error appearing in mapping->wb_err\nand the COPY worker sampling \"since\", the worker captures\nthe already-advanced cursor, errseq_check() sees cur ==\nsince and returns zero, and NFSD4_COPY_F_COMMITTED is set\neven though writeback failed. CB_OFFLOAD then encodes\nwr_stable_how = FILE_SYNC4, the client treats the copied\ndata as durable, and the failure becomes silent data loss.\n\nSample since once at the start of the function. The cursor\nthen reflects state in effect before this COPY issues any\nwrites, and filemap_check_wb_err() detects any error that\noccurs during the copy regardless of which thread first\nobserves it. This matches the pattern used by\nnfsd_vfs_write() and nfsd4_clone_file_range()."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - NFSv4.2 COPY is handled by in-kernel nfsd over TCP/UDP 2049; a remote client reaches _nfsd_copy_file_range() via COMPOUND SEQUENCE/PUTFH/OPEN/COPY with no local access on the server.\nAC:L - The attacker issues async COPY and a concurrent COMMIT or stable WRITE on the same destination inode, which share one nfsd_file/struct file, and can force writeback errors via ENOSPC or quota and retry; both sides of the race are attacker-controlled.\nPR:N - Typical nfsd exports use AUTH_SYS or AUTH_NULL with IP-based ACLs, so a network peer can spoof a UID, create an NFSv4.2 session, OPEN source and dest files, and issue COPY without a local account or capability on the NFS server.\nUI:N - The attacker sends the COPY and COMMIT RPCs themselves against an already-exported writable filesystem; no administrator or victim user action is required at exploit time.\nS:U - The missed writeback error only affects durability reporting and file data on the host running nfsd and does not cross a VM, IOMMU, or sandbox boundary.\nC:N - This is a silent durability-reporting failure, not memory disclosure; there is no out-of-bounds read, use-after-free, or kernel pointer leak.\nI:H - When a concurrent COMMIT advances dst->f_wb_err before COPY samples it, CB_OFFLOAD encodes wr_stable_how=FILE_SYNC4 despite failed writeback, so clients treat the copied range as durable and the data is silently lost after crash or cache eviction.\nA:N - The flaw does not oops, panic, deadlock, or hang nfsd; the server keeps running, and lost durability is an integrity failure rather than a kernel or NFS-service crash."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfsd/nfs4proc.c"],"versions":[{"version":"f14816f2f928c560d28ba344af689f56efcd6f55","lessThan":"435e4246c7dfff2fbd76dfdbf91975d5d9f788c9","status":"affected","versionType":"git"},{"version":"3145fe0ebb16e1715ad541a301bc6675c8375fcd","lessThan":"9f539a1c0791f907eb4e6d04b43178d9962e2def","status":"affected","versionType":"git"},{"version":"555dbf1a9aac6d3150c8b52fa35f768a692f4eeb","lessThan":"4728504c021656128a07f4693af80ed4a5fcc863","status":"affected","versionType":"git"},{"version":"555dbf1a9aac6d3150c8b52fa35f768a692f4eeb","lessThan":"322422d66d1a04434a0dcc0c9d3a4c4b3f225117","status":"affected","versionType":"git"},{"version":"555dbf1a9aac6d3150c8b52fa35f768a692f4eeb","lessThan":"52b2db7a72e19ac2686fa4b2a52406661e7bf9e2","status":"affected","versionType":"git"},{"version":"555dbf1a9aac6d3150c8b52fa35f768a692f4eeb","lessThan":"8277d4a11ae2cb5495842be558fd946032c24363","status":"affected","versionType":"git"},{"version":"555dbf1a9aac6d3150c8b52fa35f768a692f4eeb","lessThan":"a1cbafe756cd5e6ab0e099062f37da7a5b081169","status":"affected","versionType":"git"},{"version":"555dbf1a9aac6d3150c8b52fa35f768a692f4eeb","lessThan":"20a67a7d18221af736f124770c2c5e859b479046","status":"affected","versionType":"git"},{"version":"5.10.124","lessThan":"5.10.270","status":"affected","versionType":"semver"},{"version":"5.15.49","lessThan":"5.15.221","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfsd/nfs4proc.c"],"versions":[{"version":"5.17","status":"affected"},{"version":"0","lessThan":"5.17","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10.124","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15.49","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.17","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.17","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.17","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.17","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.17","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.17","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/435e4246c7dfff2fbd76dfdbf91975d5d9f788c9"},{"url":"https://git.kernel.org/stable/c/9f539a1c0791f907eb4e6d04b43178d9962e2def"},{"url":"https://git.kernel.org/stable/c/4728504c021656128a07f4693af80ed4a5fcc863"},{"url":"https://git.kernel.org/stable/c/322422d66d1a04434a0dcc0c9d3a4c4b3f225117"},{"url":"https://git.kernel.org/stable/c/52b2db7a72e19ac2686fa4b2a52406661e7bf9e2"},{"url":"https://git.kernel.org/stable/c/8277d4a11ae2cb5495842be558fd946032c24363"},{"url":"https://git.kernel.org/stable/c/a1cbafe756cd5e6ab0e099062f37da7a5b081169"},{"url":"https://git.kernel.org/stable/c/20a67a7d18221af736f124770c2c5e859b479046"}],"title":"nfsd: sample writeback error cursor before async COPY loop","x_generator":{"engine":"bippy-1.2.0"}}}}