* CVE-2026-89676: nfsd: fix stale s2s_cp_stateids IDR entry for async COPY
@ 2026-09-11 19:46 Greg Kroah-Hartman
0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-11 19:46 UTC (permalink / raw)
To: linux-cve-announce; +Cc: Greg Kroah-Hartman
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
nfsd: fix stale s2s_cp_stateids IDR entry for async COPY
For an async COPY, nfsd4_copy() called nfs4_init_copy_state() before
dup_copy_fields(), so the s2s_cp_stateids IDR was pointed at
&u->copy->cp_stateid -- memory in the per-rqstp COMPOUND buffer that is
reused by the next request. dup_copy_fields() copies only the value into
async_copy, so the IDR slot dangled at the transient buffer for the whole
background copy. Any IDR walker then dereferences reused request memory:
the laundromat reads cs_type from it and, if the bytes look like an
expired NFS4_COPYNOTIFY_STID, follows into
refcount_dec()/idr_remove()/kfree() on garbage; manage_cpntf_state() has
the same exposure via idr_find().
Duplicate the fields first, then register the stateid on the stable
async_copy. result->cb_stateid is unchanged.
The Linux kernel CVE team has assigned CVE-2026-89676 to this issue.
Affected and fixed versions
===========================
Issue introduced in 4.20 with commit e0639dc5805a9d4faaa2c07ad98fa853b9529dd3 and fixed in 6.18.50 with commit 9b4e5e9ba5ae13808b8a6d229d87c54611ba0e7a
Issue introduced in 4.20 with commit e0639dc5805a9d4faaa2c07ad98fa853b9529dd3 and fixed in 7.2.4 with commit 14b978e8d05ce018d0afbeb6611833ef91713a02
Issue introduced in 4.20 with commit e0639dc5805a9d4faaa2c07ad98fa853b9529dd3 and fixed in 7.3-rc1 with commit d0beaee498e11880e72826026db0e9c9890fc114
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-89676
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
fs/nfsd/nfs4proc.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/9b4e5e9ba5ae13808b8a6d229d87c54611ba0e7a
https://git.kernel.org/stable/c/14b978e8d05ce018d0afbeb6611833ef91713a02
https://git.kernel.org/stable/c/d0beaee498e11880e72826026db0e9c9890fc114
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-09-11 20:01 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-11 19:46 CVE-2026-89676: nfsd: fix stale s2s_cp_stateids IDR entry for async COPY Greg Kroah-Hartman
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.