# CVE-2026-89694

## Summary

- **CVE ID:** CVE-2026-89694
- **Severity:** UNKNOWN
- **CVSS Score:** 0
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 16, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

nfsd: check client ownership when cancelling a copy-notify stateid

On the OFFLOAD_CANCEL path (clp != NULL), manage_cpntf_state() freed the
target cpntf state without checking ownership. The lookup key
st->si_opaque.so_id is allocated cyclically (guessable) and the embedded
clientid is the fixed per-net nn->s2s_cp_cl_id, so any authenticated
NFSv4.2 client could cancel and free another client's copy-notify
stateid.

Compare the creating clientid recorded in state->cp_p_clid against the
requesting client's cl_clientid and return nfserr_bad_stateid on a
mismatch instead of freeing the entry.

## Affected Products

- Linux — Linux (ce0887ac96d35c7105090e166bb0807dc0a0e838)
- Linux — Linux (5.6)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)
- Linux — Linux (5.10.270)
- Linux — Linux (5.15.221)
- Linux — Linux (6.1.188)
- Linux — Linux (6.6.157)

## References

- [CNA](https://git.kernel.org/stable/c/b1eca07303594ca27f5dc360a6946bd7e1f5b04c)
- [CNA](https://git.kernel.org/stable/c/b42dc26a14b4ad5d6daaada11ec4c70744141c25)
- [CNA](https://git.kernel.org/stable/c/d801906165cb5cc250d5cbe44935594e170be3e2)
- [CNA](https://git.kernel.org/stable/c/6bdbfab96e0cf25e5f57dac5c09dc1749751a4bf)
- [CNA](https://git.kernel.org/stable/c/88daaed26e17e1c7e851859b5bbb4f0e1ab6d0e9)
- [CNA](https://git.kernel.org/stable/c/81b2cfe767943922eca906a2a5af23a0ce5d0f35)
- [CNA](https://git.kernel.org/stable/c/6bba72b8ee68ad631b94bd439592cba46de54d7d)
- [CNA](https://git.kernel.org/stable/c/75268f6cfe26b09a7e4d3216367e87fe9e2a26aa)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.21%
- **EPSS Percentile:** 11.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._