Executive brief
The Linux kernel's NFS server (NFSD) component handles file serving and copy operations over the network. A flaw in the copy-notify stateid cancellation logic allowed any authenticated NFS client to cancel and delete another client's copy operations, potentially disrupting file transfers and data integrity on NFS-based storage systems.
Technical details
The vulnerability is an authorization bypass in the manage_cpntf_state() function within fs/nfsd/nfs4state.c. When processing OFFLOAD_CANCEL requests (NFSv4.2 copy operations), the code freed copy-notify state without verifying that the requesting client owned the state being cancelled. The stateid lookup key (st->si_opaque.so_id) is allocated cyclically and predictable, and the embedded clientid is fixed per-network namespace (nn->s2s_cp_cl_id), allowing any authenticated NFSv4.2 client to forge valid-looking requests. The fix adds a clientid ownership check (memcmp of clp->cl_clientid against state->cp_p_clid) before allowing cancellation; mismatches now return nfserr_bad_stateid instead of freeing the entry. The vulnerability requires an authenticated NFSv4.2 connection but allows cross-client denial of service and potential state corruption. Patches were applied to the Linux kernel starting from commit 6bdbfab96e0cf25e5f57dac5c09dc1749751a4bf.
Affected products
- Linux Linux kernel multiple versions (patch applied from mid-2026)
Timeline
- 2026-09-11: disclosed
- 2026-08-10: patched: Upstream patch applied
- 2026-09-14: patched: Stable kernel inclusion