SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-89694

UNKNOWN · CVSS N/A EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The vulnerability in the Linux kernel affects the NFSv4.2 protocol, allowing any authenticated client to cancel and free another client's copy-notify stateid due to inadequate ownership checks during the OFFLOAD_CANCEL process. This could lead to unauthorized manipulation of client state, potentially disrupting file operations and data integrity. Organizations utilizing NFSv4.2 in their Linux environments should prioritize addressing this vulnerability to safeguard against potential exploitation.

CVE
CVE-2026-89694
Severity
UNKNOWN
CVSS
N/A
EPSS
0.20%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: nfsd: check client ownership when cancelling a copy-notify stateid On the OFFLOAD_CANCEL path (clp != NULL), manage_cpntf_state() freed the target cpntf state without checking ownership. The lookup key st->si_opaque.so_id is allocated cyclically (guessable) and the embedded clientid is the fixed per-net nn->s2s_cp_cl_id, so any authenticated NFSv4.2 client could cancel and free another client's copy-notify stateid. Compare the creating clientid recorded in state->cp_p_clid against the requesting client's cl_clientid and return nfserr_bad_stateid on a mismatch instead of freeing the entry.