Answer in brief
CVE-2026-89694 records a Unknown severity vulnerability in nfsd: check client ownership when cancelling a copy-notify stateid. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=ce0887ac96d35c7105090e166bb0807dc0a0e838 <b1eca07303594ca27f5dc360a6946bd7e1f5b04c || >=ce0887ac96d35c7105090e166bb0807dc0a0e838 <b42dc26a14b4ad5d6daaada11ec4c70744141c25 || >=ce0887ac96d35c7105090e166bb0807dc0a0e838 <d801906165cb5cc250d5cbe44935594e170be3e2 || >=ce0887ac96d35c7105090e166bb0807dc0a0e838 <6bdbfab96e0cf25e5f57dac5c09dc1749751a4bf | b1eca07303594ca27f5dc360a6946bd7e1f5b04c, b42dc26a14b4ad5d6daaada11ec4c70744141c25, d801906165cb5cc250d5cbe44935594e170be3e2, 6bdbfab96e0cf25e5f57dac5c09dc1749751a4bf |
| Linux/Linuxgeneric | 5.6 | Not reported |
Published upstream
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 11, 2026
In the Linux kernel, the following vulnerability has been resolved: nfsd: check client ownership when cancelling a copy-notify stateid On the OFFLOAD_CANCEL path (clp != NULL), manage_cpntf_state() freed the target cpntf state without checking ownership. The lookup key st->si_opaque.so_id is allocated cyclically (guessable) and the embedded clientid is the fixed per-net nn->s2s_cp_cl_id, so any authenticated NFSv4.2 client could cancel and free another client's copy-notify stateid. Compare the creating clientid recorded in state->cp_p_clid against the requesting client's cl_clientid and return nfserr_bad_stateid on a mismatch instead of freeing the entry.
Quoted source text, attributed separately from HOL analysis.