CVE-2026-89704
In the Linux kernel, the following vulnerability has been resolved:
nfsd: sample writeback error cursor before async COPY loop
_nfsd_copy_file_range() samples dst->f_wb_err into "since" after the copy loop, then uses it to detect writeback errors via filemap_check_wb_err() once vfs_fsync_range() returns. Because the nfsd_file cache reuses a single struct file across requests targeting the same inode, a concurrent COMMIT or stable WRITE on dst advances dst->f_wb_err to the current mapping->wb_err via file_check_and_advance_wb_err() during its own vfs_fsync_range().
Leer descripción completaMostrar menos
If that advancement lands between the writeback error appearing in mapping->wb_err and the COPY worker sampling "since", the worker captures the already-advanced cursor, errseq_check() sees cur == since and returns zero, and NFSD4_COPY_F_COMMITTED is set even though writeback failed. CB_OFFLOAD then encodes wr_stable_how = FILE_SYNC4, the client treats the copied data as durable, and the failure becomes silent data loss.
Sample since once at the start of the function. The cursor then reflects state in effect before this COPY issues any writes, and filemap_check_wb_err() detects any error that occurs during the copy regardless of which thread first observes it. This matches the pattern used by nfsd_vfs_write() and nfsd4_clone_file_range().
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.53%
- Percentil entre todas las CVEs puntuadas: 43
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access45 % - Impacto principal
T1565.001Stored Data Manipulationimpact80 % - Impacto secundario
T1499.004Application or System Exploitationimpact35 %
Vulnerabilidad en nfsd kernel que permite manipular errores de sincronización de archivos vía solicitudes COPY remotas (AV:N, PR:N, UI:N), causando pérdida silenciosa de datos (I:H). Afecta integridad y disponibilidad.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/20a67a7d18221af736f124770c2c5e859b479046
- https://git.kernel.org/stable/c/322422d66d1a04434a0dcc0c9d3a4c4b3f225117
- https://git.kernel.org/stable/c/435e4246c7dfff2fbd76dfdbf91975d5d9f788c9
- https://git.kernel.org/stable/c/4728504c021656128a07f4693af80ed4a5fcc863
- https://git.kernel.org/stable/c/52b2db7a72e19ac2686fa4b2a52406661e7bf9e2
- https://git.kernel.org/stable/c/8277d4a11ae2cb5495842be558fd946032c24363
- https://git.kernel.org/stable/c/9f539a1c0791f907eb4e6d04b43178d9962e2def
- https://git.kernel.org/stable/c/a1cbafe756cd5e6ab0e099062f37da7a5b081169
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-89704",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "f14816f2f928c560d28ba344af689f56efcd6f55",
"lessThan": "435e4246c7dfff2fbd76dfdbf91975d5d9f788c9",
"versionType": "git"
},
{
"status": "affected",
"version": "3145fe0ebb16e1715ad541a301bc6675c8375fcd",
"lessThan": "9f539a1c0791f907eb4e6d04b43178d9962e2def",
"versionType": "git"
},
{
"status": "affected",
"version": "555dbf1a9aac6d3150c8b52fa35f768a692f4eeb",
"lessThan": "4728504c021656128a07f4693af80ed4a5fcc863",
"versionType": "git"
},
{
"status": "affected",
"version": "555dbf1a9aac6d3150c8b52fa35f768a692f4eeb",
"lessThan": "322422d66d1a04434a0dcc0c9d3a4c4b3f225117",
"versionType": "git"
},
{
"status": "affected",
"version": "555dbf1a9aac6d3150c8b52fa35f768a692f4eeb",
"lessThan": "52b2db7a72e19ac2686fa4b2a52406661e7bf9e2",
"versionType": "git"
},
{
"status": "affected",
"version": "555dbf1a9aac6d3150c8b52fa35f768a692f4eeb",
"lessThan": "8277d4a11ae2cb5495842be558fd946032c24363",
"versionType": "git"
},
{
"status": "affected",
"version": "555dbf1a9aac6d3150c8b52fa35f768a692f4eeb",
"lessThan": "a1cbafe756cd5e6ab0e099062f37da7a5b081169",
"versionType": "git"
},
{
"status": "affected",
"version": "555dbf1a9aac6d3150c8b52fa35f768a692f4eeb",
"lessThan": "20a67a7d18221af736f124770c2c5e859b479046",
"versionType": "git"
},
{
"status": "affected",
"version": "5.10.124",
"lessThan": "5.10.270",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.15.49",
"lessThan": "5.15.221",
"versionType": "semver"
}
],
"programFiles": [
"fs/nfsd/nfs4proc.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.17"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.17",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.270",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.221",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.188",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.157",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.109",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.50",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.4",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"fs/nfsd/nfs4proc.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-11T20:19:57.657",
"references": [
{
"url": "https://git.kernel.org/stable/c/20a67a7d18221af736f124770c2c5e859b479046",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/322422d66d1a04434a0dcc0c9d3a4c4b3f225117",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/435e4246c7dfff2fbd76dfdbf91975d5d9f788c9",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/4728504c021656128a07f4693af80ed4a5fcc863",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/52b2db7a72e19ac2686fa4b2a52406661e7bf9e2",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8277d4a11ae2cb5495842be558fd946032c24363",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9f539a1c0791f907eb4e6d04b43178d9962e2def",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a1cbafe756cd5e6ab0e099062f37da7a5b081169",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: sample writeback error cursor before async COPY loop\n\n_nfsd_copy_file_range() samples dst->f_wb_err into \"since\"\nafter the copy loop, then uses it to detect writeback errors\nvia filemap_check_wb_err() once vfs_fsync_range() returns.\nBecause the nfsd_file cache reuses a single struct file\nacross requests targeting the same inode, a concurrent\nCOMMIT or stable WRITE on dst advances dst->f_wb_err to the\ncurrent mapping->wb_err via file_check_and_advance_wb_err()\nduring its own vfs_fsync_range(). If that advancement lands\nbetween the writeback error appearing in mapping->wb_err\nand the COPY worker sampling \"since\", the worker captures\nthe already-advanced cursor, errseq_check() sees cur ==\nsince and returns zero, and NFSD4_COPY_F_COMMITTED is set\neven though writeback failed. CB_OFFLOAD then encodes\nwr_stable_how = FILE_SYNC4, the client treats the copied\ndata as durable, and the failure becomes silent data loss.\n\nSample since once at the start of the function. The cursor\nthen reflects state in effect before this COPY issues any\nwrites, and filemap_check_wb_err() detects any error that\noccurs during the copy regardless of which thread first\nobserves it. This matches the pattern used by\nnfsd_vfs_write() and nfsd4_clone_file_range()."
}
],
"lastModified": "2026-09-14T13:19:20.367",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}