9.8

CVE-2026-89676

nfsd: fix stale s2s_cp_stateids IDR entry for async COPY

In the Linux kernel, the following vulnerability has been resolved:

nfsd: fix stale s2s_cp_stateids IDR entry for async COPY

For an async COPY, nfsd4_copy() called nfs4_init_copy_state() before
dup_copy_fields(), so the s2s_cp_stateids IDR was pointed at
&u->copy->cp_stateid -- memory in the per-rqstp COMPOUND buffer that is
reused by the next request. dup_copy_fields() copies only the value into
async_copy, so the IDR slot dangled at the transient buffer for the whole
background copy. Any IDR walker then dereferences reused request memory:
the laundromat reads cs_type from it and, if the bytes look like an
expired NFS4_COPYNOTIFY_STID, follows into
refcount_dec()/idr_remove()/kfree() on garbage; manage_cpntf_state() has
the same exposure via idr_find().

Duplicate the fields first, then register the stateid on the stable
async_copy. result->cb_stateid is unchanged.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version e0639dc5805a9d4faaa2c07ad98fa853b9529dd3
Version < 7aa34ea78f74e6ef60c8112635a87fc43d57f6c9
Status affected
Version e0639dc5805a9d4faaa2c07ad98fa853b9529dd3
Version < 9b4e5e9ba5ae13808b8a6d229d87c54611ba0e7a
Status affected
Version e0639dc5805a9d4faaa2c07ad98fa853b9529dd3
Version < 14b978e8d05ce018d0afbeb6611833ef91713a02
Status affected
Version e0639dc5805a9d4faaa2c07ad98fa853b9529dd3
Version < d0beaee498e11880e72826026db0e9c9890fc114
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.20
Status affected
Version 0
Version < 4.20
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.45% 0.378
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/9b4e5e9ba5ae13808b8a6d229d87c54611ba0e7a
https://git.kernel.org/stable/c/14b978e8d05ce018d0afbeb6611833ef91713a02
https://git.kernel.org/stable/c/d0beaee498e11880e72826026db0e9c9890fc114
https://git.kernel.org/stable/c/7aa34ea78f74e6ef60c8112635a87fc43d57f6c9