CVE-2026-89688
CVE CVE-2026-89688EUVD EUVD-2026-76600Published 2026-09-11T19:46:09.000ZLast changed 2026-09-13T06:33:12.000ZCVSS 9.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: nfsd: drop the stateid, not the stateowner, on seqid_op replay retry In nfs4_preprocess_seqid_op() the stateid is obtained from nfsd4_lookup_stateid(), which holds a reference on the nfs4_stid (sc_count) but takes no reference on the stateowner. openlockstateid() merely casts that stid and likewise takes no reference. When nfsd4_cstate_assign_replay() returns -EAGAIN (the replay owner is being torn down, RP_UNHASHED) it has not taken a stateowner reference on that path. The error handling nevertheless called nfs4_put_stateowner(stp->st_stateowner), dropping an so_count reference the function never acquired -- risking a stateowner refcount underflow and use-after-free -- while leaking the sc_count reference held on the stid. The leaked stid reference can also stall a concurrent nfsd4_close_open_stateid() waiting for sc_count to drop. Drop the reference actually held -- the stid -- before retrying. The stateowner stays alive through the reference held by the stid. This mirrors the open path in nfsd4_process_open1(), where the put balances a reference that path explicitly holds on the stateowner.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 6.12.109; eec7620800081e27dbf8019ac2e66259f0d5bf6f <00843074d9b84824552c9679d423d29500ca5de0; 6.10; patch: 0; patch: 6.18.50; eec7620800081e27dbf8019ac2e66259f0d5bf6f <f7cb90ddc021747fc9abfd4cf5252d425fd34eec; patch: 7.3-rc1; patch: 7.2.4; eec7620800081e27dbf8019ac2e66259f0d5bf6f <5e4627d3513e60accfce9d5f4c7fa95251ef93d6; eec7620800081e27dbf8019ac2e66259f0d5bf6f <69ed78b6b947c9257213164678b4edf17533093b
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.