CVE-2026-89694: falha em Linux
nfsd: check client ownership when cancelling a copy-notify stateid
Publicada em · Atualizada em
3Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackepss 0.2%
probabilidade de exploração
0.2%top 90% das CVEs
exploração observada
nãonenhuma fonte reporta
In the Linux kernel, the following vulnerability has been resolved:
nfsd: check client ownership when cancelling a copy-notify stateid
On the OFFLOAD_CANCEL path (clp != NULL), manage_cpntf_state() freed the
target cpntf state without checking ownership. The lookup key
st->si_opaque.so_id is allocated cyclically (guessable) and the embedded
clientid is the fixed per-net nn->s2s_cp_cl_id, so any authenticated
NFSv4.2 client could cancel and free another client's copy-notify
stateid.
Compare the creating clientid recorded in state->cp_p_clid against the
requesting client's cl_clientid and return nfserr_bad_stateid on a
mismatch instead of freeing the entry.
Produtos afetados
Linux · LinuxCVEs relacionadas — Linux
No mesmo produto, das mais perigosas para as menos.
CVE-2024-53197HIGHALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devicesEPSS 4.1%KEVCVE-2026-31431HIGHcrypto: algif_aead - Revert to operating out-of-placeEPSS 3.4%KEVCVE-2024-53104HIGHmedia: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_formatEPSS 3.4%KEVCVE-2025-39682CRITICALtls: fix handling of zero-length records on the rx_listEPSS 2.9%KEVCVE-2024-36971HIGHnet: fix __dst_negative_advice() raceEPSS 2.7%KEVCVE-2024-53150HIGHALSA: usb-audio: Fix out of bounds reads when finding clock sourcesEPSS 1.4%KEV
Referências
https://git.kernel.org/stable/c/6bba72b8ee68ad631b94bd439592cba46de54d7dhttps://git.kernel.org/stable/c/6bdbfab96e0cf25e5f57dac5c09dc1749751a4bfhttps://git.kernel.org/stable/c/75268f6cfe26b09a7e4d3216367e87fe9e2a26aahttps://git.kernel.org/stable/c/81b2cfe767943922eca906a2a5af23a0ce5d0f35https://git.kernel.org/stable/c/88daaed26e17e1c7e851859b5bbb4f0e1ab6d0e9https://git.kernel.org/stable/c/b1eca07303594ca27f5dc360a6946bd7e1f5b04chttps://git.kernel.org/stable/c/b42dc26a14b4ad5d6daaada11ec4c70744141c25https://git.kernel.org/stable/c/d801906165cb5cc250d5cbe44935594e170be3e2