CVE-2026-89706
CVE CVE-2026-89706EUVD EUVD-2026-76618Published 2026-09-11T19:46:22.000ZLast changed 2026-09-14T12:02:07.000ZCVSS 7.5
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: nfsd: Reset write verifier when async COPY writeback fails Async COPY captures nn->writeverf at request time and reports it to the client via CB_OFFLOAD after the worker kthread completes. When the post-copy vfs_fsync_range() or filemap_check_wb_err() in _nfsd_copy_file_range() reports an error, the worker correctly leaves NFSD4_COPY_F_COMMITTED clear so that CB_OFFLOAD encodes wr_stable_how as NFS_UNSTABLE, but the server's write verifier is not rotated. A client that receives NFS_UNSTABLE in CB_OFFLOAD follows up with COMMIT to make the copied data durable. With the verifier unchanged, COMMIT returns the same value the client just received via CB_OFFLOAD, and the client concludes the copy is durable -- silently dropping the data whose writeback in fact failed. This violates the UNSTABLE+COMMIT durability contract (RFC 7862 section 15.1, RFC 8881 section 18.32) and matches the bug just fixed in nfsd_vfs_write() and nfsd_commit(). Rotate nn->writeverf at the writeback-failure site. The async COPY worker has no svc_rqst, so commit_reset_write_verifier() is not available here; calling nfsd_reset_write_verifier() directly mirrors the trace-less reset already used by nfsd_file_check_write_error() for the same purpose. Filter out -EAGAIN and -ESTALE, matching commit_reset_write_verifier(), since neither indicates a durable-storage failure.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 5.14; patch: 5.10.270; eac0b17a77fbd763d305a5eaa4fd1119e5a0fe0d <31d4d0a62ec4bafbcdbad142f11ab1f90794b1d0; patch: 6.1.188; patch: 7.3-rc1; patch: 7.2.4; eac0b17a77fbd763d305a5eaa4fd1119e5a0fe0d <6b13d26cc21b6320a3c61d5e4cee2ce9a589b181; patch: 6.12.109; 817c6eb975798647c4bbbfc9eb288aa413ec7f65 <cc5f7cef0659a27c13dd33edd8e2f79257b095c6; eac0b17a77fbd763d305a5eaa4fd1119e5a0fe0d <f5cb2276954cb80987a93ef9f9dfbfdbfc0f10b9; eac0b17a77fbd763d305a5eaa4fd1119e5a0fe0d <8a08ffe73eb2aa6bc6f88763da7e2b55bab6493a; patch: 0; eac0b17a77fbd763d305a5eaa4fd1119e5a0fe0d <c6d2f6372c7e0f76b9c148ff7696aec64da0b5b7; eac0b17a77fbd763d305a5eaa4fd1119e5a0fe0d <591134e059e3456180244a826d6917cdc183140b; eac0b17a77fbd763d305a5eaa4fd1119e5a0fe0d <bf0cd31a9abcb728c17d79b4c2cc533612a8b6af; patch: 6.18.50; patch: 5.15.221; patch: 6.6.157; 5.10.220 <5.10.270
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.