{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89705","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.750Z","datePublished":"2026-09-11T19:46:21.832Z","dateUpdated":"2026-09-13T06:33:27.334Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:33:27.334Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: restore rq_status_counter to even on all nfsd_dispatch() exit paths\n\nnfsd_dispatch() sets rq_status_counter to an odd value once a request has\nbeen decoded, and back to an even value once it has been fully processed,\nforming a seq-lock like protocol with the lockless reader in\nnfsd_nl_rpc_status_get_dumpit().\n\nOnly the fully successful path restored the counter to even. The cache-hit\n(RC_REPLY), drop (RC_DROPIT / RQ_DROPME) and encode-error paths all return\nafter the odd-valued store without ever bringing the counter back to even.\nOnce one of those paths is taken, rq_status_counter is left odd: the next\nrequest's decode ORs in 1 (still odd) and only a subsequent successful\nencode restores even. While stuck odd, the dumpit reader treats the rqstp\nfields as stable and its retry check compares against the same unchanging\nodd value, so it never detects concurrent mutation. This exposes actively\nmutating fields (e.g. args->ops / args->opcnt during compound decode and\nrelease) to the lockless reader, which can read past the end of the\n8-element inline ops array.\n\nAdd a helper that advances the counter to the next even value and call it\non every return path that follows the odd-valued store. The decode-error\npath is left untouched as it is reached before the counter is set odd."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The confidentiality and availability impact is in nfsd_nl_rpc_status_get_dumpit(), reached only via NFSD_CMD_RPC_STATUS_GET over AF_NETLINK. Remote NFS RPCs can leave rq_status_counter odd in nfsd_dispatch() but never enter dumpit, so exploitation requires local netlink access.\nAC:L - An attacker can send an NFSv4.0 COMPOUND with OP_CACHEME (SETCLIENTID) and a duplicate in-flight RPC so nfsd_cache_lookup() returns RC_DROPIT, leaving rq_status_counter stuck odd. Later compounds with more than eight ops then let dumpit observe opcnt/ops mid-decode with no seqlock retry; both sides are attacker-controlled.\nPR:L - NFSD_CMD_RPC_STATUS_GET is registered with GENL_CMD_CAP_DUMP and no GENL_ADMIN_PERM, so any unprivileged process in the nfsd network namespace can invoke the dump. Exploitation does not require CAP_NET_ADMIN or init-namespace root.\nUI:N - The attacker issues the netlink dump and the NFSv4 compounds themselves. No separate victim action such as mounting a filesystem or opening a device is required.\nS:U - The slab over-read and netlink leak occur in host-kernel nfsd on the local machine. Impact stays inside one security authority and is not a VM escape, IOMMU bypass, or other cross-boundary breakout.\nC:H - With the counter stuck odd, dumpit treats mutating args->ops/opcnt as stable and reads min(opcnt,16) slots. When opcnt is set above eight before ops is switched off iops[8], indices 8-15 load adjacent slab at nfsd4_op stride and return those u32s via NFSD_A_RPC_STATUS_COMPOUND_OPS.\nI:N - dumpit only loads opnum into a stack nfsd_genl_rqstp for netlink. This seqlock bug yields an out-of-bounds read, not an out-of-bounds write, use-after-free write primitive, or control-flow hijack.\nA:H - Slots 8-15 are sampled at sizeof(struct nfsd4_op) stride past the trailing iops[8] array in kmalloc'd nfsd4_compoundargs into adjacent or unmapped slab pages, which can oops the dumpit path even if the leak is not turned into a stable read."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfsd/nfssvc.c"],"versions":[{"version":"bd9d6a3efa9709e653aafbeb859289feccb8e70c","lessThan":"b08c30f08d57f30699d36809d92f0b683dca261f","status":"affected","versionType":"git"},{"version":"bd9d6a3efa9709e653aafbeb859289feccb8e70c","lessThan":"f6045886fe3f14f269f683d64021b004a50d0efa","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfsd/nfssvc.c"],"versions":[{"version":"6.7","status":"affected"},{"version":"0","lessThan":"6.7","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.7","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.7","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/b08c30f08d57f30699d36809d92f0b683dca261f"},{"url":"https://git.kernel.org/stable/c/f6045886fe3f14f269f683d64021b004a50d0efa"}],"title":"nfsd: restore rq_status_counter to even on all nfsd_dispatch() exit paths","x_generator":{"engine":"bippy-1.2.0"}}}}