CVE-2026-89676
Gravedad CVSS v3.1:
CRÍTICA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
11/09/2026
Última modificación:
21/09/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
nfsd: fix stale s2s_cp_stateids IDR entry for async COPY<br />
<br />
For an async COPY, nfsd4_copy() called nfs4_init_copy_state() before<br />
dup_copy_fields(), so the s2s_cp_stateids IDR was pointed at<br />
&u->copy->cp_stateid -- memory in the per-rqstp COMPOUND buffer that is<br />
reused by the next request. dup_copy_fields() copies only the value into<br />
async_copy, so the IDR slot dangled at the transient buffer for the whole<br />
background copy. Any IDR walker then dereferences reused request memory:<br />
the laundromat reads cs_type from it and, if the bytes look like an<br />
expired NFS4_COPYNOTIFY_STID, follows into<br />
refcount_dec()/idr_remove()/kfree() on garbage; manage_cpntf_state() has<br />
the same exposure via idr_find().<br />
<br />
Duplicate the fields first, then register the stateid on the stable<br />
async_copy. result->cb_stateid is unchanged.
Impacto
Puntuación base 3.x
9.80
Gravedad 3.x
CRÍTICA


