Junglewise Threat Intelligence

CVE-2026-89694: Linux kernel NFSD authorization bypass in copy-notify stateid cancellation

CVE-2026-89694 · Severity: info · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's NFS server (NFSD) component handles file serving and copy operations over the network. A flaw in the copy-notify stateid cancellation logic allowed any authenticated NFS client to cancel and delete another client's copy operations, potentially disrupting file transfers and data integrity on NFS-based storage systems.

Technical details

The vulnerability is an authorization bypass in the manage_cpntf_state() function within fs/nfsd/nfs4state.c. When processing OFFLOAD_CANCEL requests (NFSv4.2 copy operations), the code freed copy-notify state without verifying that the requesting client owned the state being cancelled. The stateid lookup key (st->si_opaque.so_id) is allocated cyclically and predictable, and the embedded clientid is fixed per-network namespace (nn->s2s_cp_cl_id), allowing any authenticated NFSv4.2 client to forge valid-looking requests. The fix adds a clientid ownership check (memcmp of clp->cl_clientid against state->cp_p_clid) before allowing cancellation; mismatches now return nfserr_bad_stateid instead of freeing the entry. The vulnerability requires an authenticated NFSv4.2 connection but allows cross-client denial of service and potential state corruption. Patches were applied to the Linux kernel starting from commit 6bdbfab96e0cf25e5f57dac5c09dc1749751a4bf.

Affected products

  • Linux Linux kernel multiple versions (patch applied from mid-2026)

Timeline

  • 2026-09-11: disclosed
  • 2026-08-10: patched: Upstream patch applied
  • 2026-09-14: patched: Stable kernel inclusion

References

Related threats