9.8

CVE-2026-89669

nfsd: initialize copy-notify stateid before publishing it

In the Linux kernel, the following vulnerability has been resolved:

nfsd: initialize copy-notify stateid before publishing it

nfsd4_copy_notify() finished initializing the cpntf state after
nfs4_alloc_init_cpntf_state() had already linked it into the
s2s_cp_stateids IDR and the parent's sc_cp_list, with cs_count == 1 (the
membership reference) and none held for the caller. A racing
OFFLOAD_CANCEL (crafted cl_id == nn->s2s_cp_cl_id plus the guessable
so_id) could reach manage_cpntf_state() and free the entry, turning the
caller's subsequent cpn_cnr_stateid read and cp_p_stateid/cp_p_clid
writes into use-after-free. The owning clientid was also only recorded
after publication, so it could not gate an ownership check in that window.

Record cp_p_stateid and cp_p_clid inside nfs4_alloc_init_cpntf_state()
before nfs4_init_cp_state() publishes the entry, and return it with an
extra reference. The caller reads the stateid under that reference and
drops it with nfs4_put_cpntf_state(); on a late error the laundromat
reaps the entry.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 624322f1adc58acd0b69f77a6ddc764207e97241
Version < 863b6e995665472f2af5be2436a874ab6a9e5ac6
Status affected
Version 624322f1adc58acd0b69f77a6ddc764207e97241
Version < d18d36395d973ef7372c8e6724970585f75b5c0b
Status affected
Version 624322f1adc58acd0b69f77a6ddc764207e97241
Version < 4415a692346a39fdb647cbd717eda510159aaf55
Status affected
Version 624322f1adc58acd0b69f77a6ddc764207e97241
Version < 9caad13b7cfe9ccb90cc405ac77335800e086595
Status affected
Version 624322f1adc58acd0b69f77a6ddc764207e97241
Version < e08a3dcaca0505f861e344a387f37f94d95dbdc2
Status affected
Version 624322f1adc58acd0b69f77a6ddc764207e97241
Version < a4d7fedcaaf33e60a01e53eafca9041ef966212f
Status affected
Version 624322f1adc58acd0b69f77a6ddc764207e97241
Version < 4cdef96892f4fa6e70c405b6e8f2fd6972f3b64b
Status affected
Version 624322f1adc58acd0b69f77a6ddc764207e97241
Version < 129643893b79f8a3c6b72045f933fbab5ee424ca
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.6
Status affected
Version 0
Version < 5.6
Status unaffected
Version <= 5.10.*
Version 5.10.270
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.61% 0.472
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/e08a3dcaca0505f861e344a387f37f94d95dbdc2
https://git.kernel.org/stable/c/a4d7fedcaaf33e60a01e53eafca9041ef966212f
https://git.kernel.org/stable/c/4cdef96892f4fa6e70c405b6e8f2fd6972f3b64b
https://git.kernel.org/stable/c/129643893b79f8a3c6b72045f933fbab5ee424ca
https://git.kernel.org/stable/c/4415a692346a39fdb647cbd717eda510159aaf55
https://git.kernel.org/stable/c/863b6e995665472f2af5be2436a874ab6a9e5ac6
https://git.kernel.org/stable/c/9caad13b7cfe9ccb90cc405ac77335800e086595
https://git.kernel.org/stable/c/d18d36395d973ef7372c8e6724970585f75b5c0b