From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 86BF558FD0C for ; Fri, 11 Sep 2026 20:03:31 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789157021; cv=none; b=sh25pbbw2IrzeeuOs+ZFu6GTbuYh7qBrdpIjkTeOAyQQnV8N0n9kcZBN2lRJKhkZ9kePFCRmyvtz0nScru08MhPVBhaI8cjLw1dA1Rv6XLIbzz4YEfksVbBtxvuuUJBiwX8PV+ixhlflIm6R2aZo2vzfE7pncyiTIiNHJgUiVPw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789157021; c=relaxed/simple; bh=u5jPDoPFmfwHN8omzkprlndkOBbUHicASoTS+mC/H5M=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=npB0dJjde4f/M18e6lDCUAalMY1IKs44YmWfsI0i9LYrtDNOFt4Y7lEaEtpo4HCoTNjvuGNg+6MteWxXgbiL21HfFLqc5gVuSR4AaaiTRZNUfK1Dyb9FHNXo7VyrYEo+lP4HDySnZ6BgOvFgrBYpPgCprJaF1JK5bCAMaY/VgWw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=TPF7J+xD; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="TPF7J+xD" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 5F4691F0089A; Fri, 11 Sep 2026 20:03:20 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789157000; bh=KX8rzMA2KXCAtJyunw2oQhIvjh3JxW5zIqDcYdsKgsE=; h=From:To:Cc:Subject:Date:Reply-To; b=TPF7J+xDp9ULSNlcPMjeuAifGeW4cyDT2j/lk/ccs/3+Bf/h458DR/8LyvBrsmioa 4y8R5lDR2OpVoFIfDkjhSUD8uG6Z8tJcPQ2pXbIJbXG7s/hN0IzllmXl2rerr5qgNt s3dgCcp4x+j3u0BbfBIHFAeETH8Aty0iLMSGLoDc= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89669: nfsd: initialize copy-notify stateid before publishing it Date: Fri, 11 Sep 2026 21:45:58 +0200 Message-ID: <2026091148-CVE-2026-89669-53f8@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3165; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=pdtduHPS3VcRbgIlCfXAD46HEna0N3XiRIe4x3Zg3W8=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLImvWvpN7Z2vLN7F0nV305V3e0m2FMX2Ov3fY3Spuj eH+oyzeEcvCIMjEICumyPJlG8/R/RWHFL0MbU/DzGFlAhnCwMUpABO5sIhhQYdb7aXyHxyPFgX6 6L/889F1+/e7fxnm1wpfvPh1188Xx/kvmB2/9O/lx2dl/wA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: nfsd: initialize copy-notify stateid before publishing it nfsd4_copy_notify() finished initializing the cpntf state after nfs4_alloc_init_cpntf_state() had already linked it into the s2s_cp_stateids IDR and the parent's sc_cp_list, with cs_count == 1 (the membership reference) and none held for the caller. A racing OFFLOAD_CANCEL (crafted cl_id == nn->s2s_cp_cl_id plus the guessable so_id) could reach manage_cpntf_state() and free the entry, turning the caller's subsequent cpn_cnr_stateid read and cp_p_stateid/cp_p_clid writes into use-after-free. The owning clientid was also only recorded after publication, so it could not gate an ownership check in that window. Record cp_p_stateid and cp_p_clid inside nfs4_alloc_init_cpntf_state() before nfs4_init_cp_state() publishes the entry, and return it with an extra reference. The caller reads the stateid under that reference and drops it with nfs4_put_cpntf_state(); on a late error the laundromat reaps the entry. The Linux kernel CVE team has assigned CVE-2026-89669 to this issue. Affected and fixed versions =========================== Issue introduced in 5.6 with commit 624322f1adc58acd0b69f77a6ddc764207e97241 and fixed in 6.12.109 with commit e08a3dcaca0505f861e344a387f37f94d95dbdc2 Issue introduced in 5.6 with commit 624322f1adc58acd0b69f77a6ddc764207e97241 and fixed in 6.18.50 with commit a4d7fedcaaf33e60a01e53eafca9041ef966212f Issue introduced in 5.6 with commit 624322f1adc58acd0b69f77a6ddc764207e97241 and fixed in 7.2.4 with commit 4cdef96892f4fa6e70c405b6e8f2fd6972f3b64b Issue introduced in 5.6 with commit 624322f1adc58acd0b69f77a6ddc764207e97241 and fixed in 7.3-rc1 with commit 129643893b79f8a3c6b72045f933fbab5ee424ca Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89669 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: fs/nfsd/nfs4proc.c fs/nfsd/nfs4state.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/e08a3dcaca0505f861e344a387f37f94d95dbdc2 https://git.kernel.org/stable/c/a4d7fedcaaf33e60a01e53eafca9041ef966212f https://git.kernel.org/stable/c/4cdef96892f4fa6e70c405b6e8f2fd6972f3b64b https://git.kernel.org/stable/c/129643893b79f8a3c6b72045f933fbab5ee424ca