Executive brief
The Linux kernel's NFS server implementation contains a race condition in its COPY_NOTIFY operation that can lead to use-after-free memory corruption. An attacker with network access can craft a malicious NFS request sequence to trigger the vulnerability, potentially enabling denial of service or arbitrary code execution on systems running the affected kernel versions.
Technical details
The vulnerability is a use-after-free in the nfsd4_copy_notify() function, specifically in the copy-notify stateid initialization flow. The root cause is a race condition: nfs4_alloc_init_cpntf_state() publishes the cpntf state structure into the s2s_cp_stateids IDR and parent's sc_cp_list before initialization is complete (with only a membership reference, cs_count==1, and none for the caller). A concurrent OFFLOAD_CANCEL operation with a crafted client ID (matching nn->s2s_cp_cl_id) and guessable state ID can reach manage_cpntf_state() and free the entry. The original caller then performs reads and writes to the freed memory (cpn_cnr_stateid, cp_p_stateid, cp_p_clid), resulting in use-after-free. Additionally, the owning clientid is recorded after publication, preventing ownership validation during the vulnerable window. The fix moves initialization of cp_p_stateid and cp_p_clid into nfs4_alloc_init_cpntf_state() before publishing, returns an extra reference to the caller, and properly manages reference counting to prevent premature freeing. No user interaction is required; the attack is network-triggered.
Affected products
- Linux Linux kernel Multiple versions affected; fix applied upstream and to stable kernels
Timeline
- 2026-09-11: disclosed: CVE-2026-89669 published on NVD
- 2026-08-10: patched: Fix committed upstream (commit 129643893b79f8a3c6b72045f933fbab5ee424ca) and backported to stable kernels (e.g., commit 4415a692346a39fdb647cbd717eda510159aaf55)