CVE-2026-89684
Reported by Linux · Published September 11, 2026
In the Linux kernel, the following vulnerability has been resolved: nfsd: fix cpntf publish race in nfs4_init_cp_state nfs4_alloc_init_cpntf_state() published the new cpntf entry into the s2s_cp_stateids IDR (with cs_type set) in one s2s_cp_lock section, then took the lock again to list_add() it onto p_stid->sc_cp_list. In the gap the entry is reachable by so_id but cp_list is still {NULL,NULL} from kzalloc. A racing OFFLOAD_CANCEL (so_id is echoed to the client as cnr_stateid, so any NFSv4.2 client can drive it) reaches manage_cpntf_state() -> _free_cpntf_state_locked() and does list_del() on the zeroed list_head, oopsing the server. Fold the cs_type assignment and the list_add() into the same critical section as idr_alloc_cyclic(), so a concurrent lookup either misses the entry or sees a fully linked cp_list. INIT_LIST_HEAD() the entry after allocation and switch _free_cpntf_state_locked() to list_del_init() so a stale unlink is a no-op. nfs4_init_copy_state() passes NULL p_stid and skips the list_add, preserving NFS4_COPY_STID semantics.
EPSS 0.51% · 42.3th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | 624322f1adc58acd0b69f77a6ddc764207e97241, 624322f1adc58acd0b69f77a6ddc764207e97241, 624322f1adc58acd0b69f77a6ddc764207e97241 |
| Linux | Linux | 5.6, 0, 5.10.270 |
| linux | linux_kernel | 5.6, 5.6, 5.6 |
| Linux | Linux | 624322f1adc58acd0b69f77a6ddc764207e97241, 624322f1adc58acd0b69f77a6ddc764207e97241, 624322f1adc58acd0b69f77a6ddc764207e97241 |
Timeline
- Sep 11, 2026 Coalition ESS Score
- Sep 11, 2026 CVE Published
- Sep 12, 2026 EPSS Score
- Sep 13, 2026 EPSS Score
- Sep 14, 2026 CVE Updated
- Sep 15, 2026 EPSS Score
- Sep 16, 2026 EPSS Score
- Sep 18, 2026 EPSS Score