CVE-2026-89676

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/09/2026
Last modified:
21/09/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> nfsd: fix stale s2s_cp_stateids IDR entry for async COPY<br /> <br /> For an async COPY, nfsd4_copy() called nfs4_init_copy_state() before<br /> dup_copy_fields(), so the s2s_cp_stateids IDR was pointed at<br /> &amp;u-&gt;copy-&gt;cp_stateid -- memory in the per-rqstp COMPOUND buffer that is<br /> reused by the next request. dup_copy_fields() copies only the value into<br /> async_copy, so the IDR slot dangled at the transient buffer for the whole<br /> background copy. Any IDR walker then dereferences reused request memory:<br /> the laundromat reads cs_type from it and, if the bytes look like an<br /> expired NFS4_COPYNOTIFY_STID, follows into<br /> refcount_dec()/idr_remove()/kfree() on garbage; manage_cpntf_state() has<br /> the same exposure via idr_find().<br /> <br /> Duplicate the fields first, then register the stateid on the stable<br /> async_copy. result-&gt;cb_stateid is unchanged.