Expired pointer dereference in Linux kernel - CVE-2026-89676
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an expired pointer dereference in the nfsd asynchronous COPY stateid IDR handling when processing asynchronous NFS COPY requests. A remote attacker can submit an asynchronous COPY request to cause a denial of service.
Exploitation requires an IDR walker to dereference reused request memory whose contents resemble an expired NFS4_COPYNOTIFY_STID.