Description
In the Linux kernel, the following vulnerability has been resolved:

nfsd: fix stale s2s_cp_stateids IDR entry for async COPY

For an async COPY, nfsd4_copy() called nfs4_init_copy_state() before
dup_copy_fields(), so the s2s_cp_stateids IDR was pointed at
&u->copy->cp_stateid -- memory in the per-rqstp COMPOUND buffer that is
reused by the next request. dup_copy_fields() copies only the value into
async_copy, so the IDR slot dangled at the transient buffer for the whole
background copy. Any IDR walker then dereferences reused request memory:
the laundromat reads cs_type from it and, if the bytes look like an
expired NFS4_COPYNOTIFY_STID, follows into
refcount_dec()/idr_remove()/kfree() on garbage; manage_cpntf_state() has
the same exposure via idr_find().

Duplicate the fields first, then register the stateid on the stable
async_copy. result->cb_stateid is unchanged.
Published: 2026-09-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

The vulnerability arises when an asynchronous COPY operation in the NFSv4 server leaves a stale IDR entry pointing to a per‑request buffer that is subsequently reused. An IDR traversal that dereferences this dangling entry triggers kernel memory reclamation code to act on garbage, causing a kernel panic. This results in a denial of service. The weakness is classified as CWE-825, improper removal and deallocation of a resource. The CVSS score of 9.8 indicates a critical risk, and although the high.

Affected Systems

All Linux kernel builds that include the NFSv4 server with the async COPY feature enabled are vulnerable. The affected product is the Linux kernel. No precise version range is supplied by the CNA.

Risk and Exploitability

The likely attack vector involves an NFSv4 client issuing a manipulated asynchronous COPY request. Any remote NFS client can trigger the flaw, categorizing this vulnerability as critical. The EPSS score is below 1%, suggesting a very low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Consequently, the risk is moderate due to low exploitation likelihood, but if exploited it would cause a system crash.

Generated by OpenCVE AI on September 15, 2026 at 20:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel update that contains the NFSv4 async COPY patch to remove the stale IDR issue.
  • If the update is not available, disable the async COPY feature in operations to be synchronous to avoid the stale IDR condition.
  • Enable kernel IDR debugging and configure the system logger to alert on IDR misuse, then monitor logs for anomalous errors related to NFSv4 COPY operations.

Generated by OpenCVE AI on September 15, 2026 at 20:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 21 Sep 2026 13:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nfsd: fix stale s2s_cp_stateids IDR entry for async COPY For an async COPY, nfsd4_copy() called nfs4_init_copy_state() before dup_copy_fields(), so the s2s_cp_stateids IDR was pointed at &u->copy->cp_stateid -- memory in the per-rqstp COMPOUND buffer that is reused by the next request. dup_copy_fields() copies only the value into async_copy, so the IDR slot dangled at the transient buffer for the whole background copy. Any IDR walker then dereferences reused request memory: the laundromat reads cs_type from it and, if the bytes look like an expired NFS4_COPYNOTIFY_STID, follows into refcount_dec()/idr_remove()/kfree() on garbage; manage_cpntf_state() has the same exposure via idr_find(). Duplicate the fields first, then register the stateid on the stable async_copy. result->cb_stateid is unchanged.
Title nfsd: fix stale s2s_cp_stateids IDR entry for async COPY
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-21T13:14:43.984Z

Reserved: 2026-09-11T19:38:34.747Z

Link: CVE-2026-89676

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:54.273

Modified: 2026-09-21T14:17:25.073

Link: CVE-2026-89676

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:00Z

Links: CVE-2026-89676 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:30:10Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference