Description
In the Linux kernel, the following vulnerability has been resolved:

nfsd: check client ownership when cancelling a copy-notify stateid

On the OFFLOAD_CANCEL path (clp != NULL), manage_cpntf_state() freed the
target cpntf state without checking ownership. The lookup key
st->si_opaque.so_id is allocated cyclically (guessable) and the embedded
clientid is the fixed per-net nn->s2s_cp_cl_id, so any authenticated
NFSv4.2 client could cancel and free another client's copy-notify
stateid.

Compare the creating clientid recorded in state->cp_p_clid against the
requesting client's cl_clientid and return nfserr_bad_stateid on a
mismatch instead of freeing the entry.
Published: 2026-09-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

In the Linux kernel NFS daemon, the OFFLOAD_CANCEL routine can free a copy‑notify state without verifying that the requesting client owns the state. This allows an authenticated NFSv4.2 client to cancel another client’s state, causing loss of that client’s transaction state and potential data loss or service disruption. The flaw is an authorization weakness classified as CWE-639.

Affected Systems

All Linux kernel releases that have not yet implemented the ownership check in the nfsd module are vulnerable. Any distribution hosting an NFSv4.2 server on such a kernel is affected, regardless of specific vendor or patch level.

Risk and Exploitability

The vulnerability has a CVSS score of 5.3, indicating medium severity, while the EPSS probability is less than 1 %, showing low current exploitation likelihood. It is not listed in CISA’s KEV catalog. Attackers must authenticate to the NFS server via NFSv4.2 and send OFFLOAD_CANCEL commands, so the vector is the NFS protocol over the network; exposure to untrusted networks increases risk.

Generated by OpenCVE AI on September 15, 2026 at 20:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that includes the ownership validation fix for the nfsd OFFLOAD_CANCEL path.
  • If a kernel upgrade is impractical, disable NFSv4.2 support or restrict it to a trusted IP range so that only authorized clients can connect.
  • Configure firewall rules to limit inbound traffic to the NFS server’s NFS port (2049) to known, trusted hosts.
  • Enable and monitor NFS audit logging to detect any anomalous OFFLOAD_CANCEL requests that may indicate an attempt to cancel other clients’ states.

Generated by OpenCVE AI on September 15, 2026 at 20:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nfsd: check client ownership when cancelling a copy-notify stateid On the OFFLOAD_CANCEL path (clp != NULL), manage_cpntf_state() freed the target cpntf state without checking ownership. The lookup key st->si_opaque.so_id is allocated cyclically (guessable) and the embedded clientid is the fixed per-net nn->s2s_cp_cl_id, so any authenticated NFSv4.2 client could cancel and free another client's copy-notify stateid. Compare the creating clientid recorded in state->cp_p_clid against the requesting client's cl_clientid and return nfserr_bad_stateid on a mismatch instead of freeing the entry.
Title nfsd: check client ownership when cancelling a copy-notify stateid
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:02:02.130Z

Reserved: 2026-09-11T19:38:34.749Z

Link: CVE-2026-89694

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:56.490

Modified: 2026-09-14T13:19:19.767

Link: CVE-2026-89694

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:46:13Z

Links: CVE-2026-89694 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:00:17Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key