Description
In the Linux kernel, the following vulnerability has been resolved:

nfsd: drop the stateid, not the stateowner, on seqid_op replay retry

In nfs4_preprocess_seqid_op() the stateid is obtained from
nfsd4_lookup_stateid(), which holds a reference on the nfs4_stid
(sc_count) but takes no reference on the stateowner. openlockstateid()
merely casts that stid and likewise takes no reference.

When nfsd4_cstate_assign_replay() returns -EAGAIN (the replay owner is
being torn down, RP_UNHASHED) it has not taken a stateowner reference on
that path. The error handling nevertheless called
nfs4_put_stateowner(stp->st_stateowner), dropping an so_count reference
the function never acquired -- risking a stateowner refcount underflow and
use-after-free -- while leaking the sc_count reference held on the stid.
The leaked stid reference can also stall a concurrent
nfsd4_close_open_stateid() waiting for sc_count to drop.

Drop the reference actually held -- the stid -- before retrying. The
stateowner stays alive through the reference held by the stid. This mirrors
the open path in nfsd4_process_open1(), where the put balances a reference
that path explicitly holds on the stateowner.
Published: 2026-09-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free
Action: Apply patch
AI Analysis

Impact

In the Linux kernel NFS daemon, replay of a seqid operation can drop a reference to a state owner that was never taken, causing a reference count underflow on the stateowner and leaving a leaked state ID reference that can stall concurrent close operations. This flaw is an instance of improper resource management (CWE-825) that can lead to a use‑after‑free scenario within the kernel, potentially corrupting memory or crashing the system.

Affected Systems

The vulnerability resides in the NFSv4 implementation of the Linux kernel and affects all Linux distributions that ship the standard kernel, regardless of vendor. No specific kernel versions are listed in the data, indicating that the issue may exist in multiple recent releases until patched via an update.

Risk and Exploitability

The CVSS score of 9.8 denotes critical severity. The EPSS rank of <1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in CISA KEV. The issue can be triggered by a replayed seqid operation that causes an EAGAIN path dropping an unacquired stateowner reference, leading to a kernel reference count underflow and use‑after‑free, potentially crashing the system. Based on the description, it is inferred that an attacker would need the ability to send or influence NFSv4 requests to a vulnerable server, making the attack vector likely remote NFS traffic. Given the low EPSS and lack of public exploitation, the risk is critical but currently low likelihood.

Generated by OpenCVE AI on September 15, 2026 at 20:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a release that contains the CVE‑2026‑89688 fix, which corrects the CWE‑825 reference counting bug in NFSd.
  • If an upgrade cannot be performed immediately, disable NFSv4 on the server or restrict NFSv4 traffic to trusted hosts using firewall or kernel configuration to reduce exposure to the reference count underflow.
  • After applying the patch, monitor system logs and kernel crash reports for any NFS‑related crashes or anomalous memory usage to confirm that the reference counting issue has been resolved.

Generated by OpenCVE AI on September 15, 2026 at 20:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nfsd: drop the stateid, not the stateowner, on seqid_op replay retry In nfs4_preprocess_seqid_op() the stateid is obtained from nfsd4_lookup_stateid(), which holds a reference on the nfs4_stid (sc_count) but takes no reference on the stateowner. openlockstateid() merely casts that stid and likewise takes no reference. When nfsd4_cstate_assign_replay() returns -EAGAIN (the replay owner is being torn down, RP_UNHASHED) it has not taken a stateowner reference on that path. The error handling nevertheless called nfs4_put_stateowner(stp->st_stateowner), dropping an so_count reference the function never acquired -- risking a stateowner refcount underflow and use-after-free -- while leaking the sc_count reference held on the stid. The leaked stid reference can also stall a concurrent nfsd4_close_open_stateid() waiting for sc_count to drop. Drop the reference actually held -- the stid -- before retrying. The stateowner stays alive through the reference held by the stid. This mirrors the open path in nfsd4_process_open1(), where the put balances a reference that path explicitly holds on the stateowner.
Title nfsd: drop the stateid, not the stateowner, on seqid_op replay retry
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:33:12.290Z

Reserved: 2026-09-11T19:38:34.749Z

Link: CVE-2026-89688

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:55.773

Modified: 2026-09-13T07:17:34.600

Link: CVE-2026-89688

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:46:09Z

Links: CVE-2026-89688 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:45:20Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference