CyberRota Analysis
AI-GeneratedThe vulnerability in the Linux kernel affects the NFSv4.2 protocol, allowing any authenticated client to cancel and free another client's copy-notify stateid due to inadequate ownership checks during the OFFLOAD_CANCEL process. This could lead to unauthorized manipulation of client state, potentially disrupting file operations and data integrity. Organizations utilizing NFSv4.2 in their Linux environments should prioritize addressing this vulnerability to safeguard against potential exploitation.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: nfsd: check client ownership when cancelling a copy-notify stateid On the OFFLOAD_CANCEL path (clp != NULL), manage_cpntf_state() freed the target cpntf state without checking ownership. The lookup key st->si_opaque.so_id is allocated cyclically (guessable) and the embedded clientid is the fixed per-net nn->s2s_cp_cl_id, so any authenticated NFSv4.2 client could cancel and free another client's copy-notify stateid. Compare the creating clientid recorded in state->cp_p_clid against the requesting client's cl_clientid and return nfserr_bad_stateid on a mismatch instead of freeing the entry.