Description
In the Linux kernel, the following vulnerability has been resolved:

nfsd: fix cpntf publish race in nfs4_init_cp_state

nfs4_alloc_init_cpntf_state() published the new cpntf entry into the
s2s_cp_stateids IDR (with cs_type set) in one s2s_cp_lock section, then
took the lock again to list_add() it onto p_stid->sc_cp_list. In the gap
the entry is reachable by so_id but cp_list is still {NULL,NULL} from
kzalloc. A racing OFFLOAD_CANCEL (so_id is echoed to the client as
cnr_stateid, so any NFSv4.2 client can drive it) reaches
manage_cpntf_state() -> _free_cpntf_state_locked() and does list_del() on
the zeroed list_head, oopsing the server.

Fold the cs_type assignment and the list_add() into the same critical
section as idr_alloc_cyclic(), so a concurrent lookup either misses the
entry or sees a fully linked cp_list. INIT_LIST_HEAD() the entry after
allocation and switch _free_cpntf_state_locked() to list_del_init() so a
stale unlink is a no-op. nfs4_init_copy_state() passes NULL p_stid and
skips the list_add, preserving NFS4_COPY_STID semantics.
Published: 2026-09-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via NFS server crash
Action: Apply Patch
AI Analysis

Impact

The flaw is a race condition in the Linux NFS server (nfsd) that occurs during the initialization of client notification state. An uninitialized OFFLOAD_CANCEL request from an NFSv4.2 client can cause the kernel to attempt a list_del on a zeroed list_head, producing an oops and crashing the NFS daemon. The resulting kernel panic shuts down the NFS service, exposing all clients to a denial of service. This weakness maps to list handling race conditions (CWE-824).

Affected Systems

The vulnerability affects any Linux kernel that contains the nfs4_init_cp_state path without the latest patch. All distributions running an unpatched kernel are potentially impacted. The fix was introduced in the recent kernel series, so versions prior to that commit remain vulnerable.

Risk and Exploitability

The CVSS score of 7.5 signals high severity, while the EPSS score of less than 1 % indicates a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. An attacker would need access to the NFS service and the ability to issue an OFFLOAD_CANCEL request as an NFSv4.2 client to trigger the race and cause a crash.

Generated by OpenCVE AI on September 15, 2026 at 20:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the commit fixing the nfs4_init_cp_state race.
  • Restart the NFS service to make the new kernel code active.
  • If an upgrade cannot be performed immediately, limit NFSv4.2 client access to trusted hosts or disable OFFLOAD_CANCEL handling through NFS configuration to reduce the race window.

Generated by OpenCVE AI on September 15, 2026 at 20:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-824
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nfsd: fix cpntf publish race in nfs4_init_cp_state nfs4_alloc_init_cpntf_state() published the new cpntf entry into the s2s_cp_stateids IDR (with cs_type set) in one s2s_cp_lock section, then took the lock again to list_add() it onto p_stid->sc_cp_list. In the gap the entry is reachable by so_id but cp_list is still {NULL,NULL} from kzalloc. A racing OFFLOAD_CANCEL (so_id is echoed to the client as cnr_stateid, so any NFSv4.2 client can drive it) reaches manage_cpntf_state() -> _free_cpntf_state_locked() and does list_del() on the zeroed list_head, oopsing the server. Fold the cs_type assignment and the list_add() into the same critical section as idr_alloc_cyclic(), so a concurrent lookup either misses the entry or sees a fully linked cp_list. INIT_LIST_HEAD() the entry after allocation and switch _free_cpntf_state_locked() to list_del_init() so a stale unlink is a no-op. nfs4_init_copy_state() passes NULL p_stid and skips the list_add, preserving NFS4_COPY_STID semantics.
Title nfsd: fix cpntf publish race in nfs4_init_cp_state
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:02:01.056Z

Reserved: 2026-09-11T19:38:34.748Z

Link: CVE-2026-89684

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:55.300

Modified: 2026-09-14T13:19:19.610

Link: CVE-2026-89684

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:06Z

Links: CVE-2026-89684 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:30:10Z

Weaknesses
  • CWE-824

    Access of Uninitialized Pointer