In the Linux kernel, the following vulnerability has been resolved:
nfsd: check client ownership when cancelling a copy-notify stateid
On the OFFLOAD_CANCEL path (clp != NULL), manage_cpntf_state() freed the
target cpntf state without checking ownership. The lookup key
st->si_opaque.so_id is allocated cyclically (guessable) and the embedded
clientid is the fixed per-net nn->s2s_cp_cl_id, so any authenticated
NFSv4.2 client could cancel and free another client's copy-notify
stateid.
Compare the creating clientid recorded in state->cp_p_clid against the
requesting client's cl_clientid and return nfserr_bad_stateid on a
mismatch instead of freeing the entry.
CVE-2026-89694
NONE
EPSS 0.21%
Updated Sep 14, 2026
Linux
https://git.kernel.org/stable/c/6bdbfab96e0cf25e5f57dac5c09dc1749751a4bf
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/b1eca07303594ca27f5dc360a6946bd7e1f5b04c
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/b42dc26a14b4ad5d6daaada11ec4c70744141c25
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/d801906165cb5cc250d5cbe44935594e170be3e2
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/6bba72b8ee68ad631b94bd439592cba46de54d7d
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/75268f6cfe26b09a7e4d3216367e87fe9e2a26aa
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/81b2cfe767943922eca906a2a5af23a0ce5d0f35
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/88daaed26e17e1c7e851859b5bbb4f0e1ab6d0e9
416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVE Details
CVE ID
CVE-2026-89694
Published Date
Sep 11, 2026
Vendor
Linux
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.21%
Likelihood of exploitation in next 30 days
Percentile:
10.4th percentile (higher than 10.4% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory