{"id":"CVE-2026-89704","title":"kernel: nfsd: sample writeback error cursor before async COPY loop (CVE-2026-89704)","summary":"A flaw was found in the Linux kernel's nfsd component. The _nfsd_copy_file_range() function incorrectly samples the writeback error cursor after the copy loop. This allows a concurrent write operation to advance the error cursor prematurel…","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-367","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","affected":["enterprise_linux 10","enterprise_linux 6","enterprise_linux 9","openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-21","sourceUpdated":"2026-09-21T14:17:30+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89704.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89704.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89704"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532298"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89704"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89704"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89704.mbox"},{"url":"https://git.kernel.org/stable/c/435e4246c7dfff2fbd76dfdbf91975d5d9f788c9"},{"url":"https://git.kernel.org/stable/c/9f539a1c0791f907eb4e6d04b43178d9962e2def"},{"url":"https://git.kernel.org/stable/c/4728504c021656128a07f4693af80ed4a5fcc863"},{"url":"https://git.kernel.org/stable/c/322422d66d1a04434a0dcc0c9d3a4c4b3f225117"},{"url":"https://git.kernel.org/stable/c/52b2db7a72e19ac2686fa4b2a52406661e7bf9e2"},{"url":"https://git.kernel.org/stable/c/8277d4a11ae2cb5495842be558fd946032c24363"},{"url":"https://git.kernel.org/stable/c/a1cbafe756cd5e6ab0e099062f37da7a5b081169"},{"url":"https://git.kernel.org/stable/c/20a67a7d18221af736f124770c2c5e859b479046"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00511,"epssPercentile":0.42464,"scores":{"vendor":7,"cna":7.5},"ingestedAt":"2026-09-14T15:23:07.449Z","slug":"CVE-2026-89704","body":"## Overview\n\nA flaw was found in the Linux kernel's nfsd component. The _nfsd_copy_file_range() function incorrectly samples the writeback error cursor after the copy loop. This allows a concurrent write operation to advance the error cursor prematurely. As a result, the system may report that data has been successfully committed even when writeback errors have occurred, leading to silent data loss where clients perceive data as durable when it is not.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89704.json)\n\n**kernel: nfsd: sample writeback error cursor before async COPY loop** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-21.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNot affected:\n\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nOut of support scope","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":208451,"id":"CVE-2026-89704","ts":1790005705030,"field":"cvss","old":"7.5","new":"7"},{"seq":197720,"id":"CVE-2026-89704","ts":1789384318541,"field":"cvss","old":"6.8","new":"7.5"},{"seq":197719,"id":"CVE-2026-89704","ts":1789384318541,"field":"severity","old":"medium","new":"high"},{"seq":183670,"id":"CVE-2026-89704","ts":1789356676871,"field":"cvss","old":"7.5","new":"6.8"},{"seq":183669,"id":"CVE-2026-89704","ts":1789356676871,"field":"severity","old":"high","new":"medium"},{"seq":153588,"id":"CVE-2026-89704","ts":1789285351395,"field":"cvss","old":null,"new":"7.5"},{"seq":153587,"id":"CVE-2026-89704","ts":1789285351395,"field":"severity","old":"none","new":"high"},{"seq":147426,"id":"CVE-2026-89704","ts":1789270210862,"field":"cvss","old":null,"new":"6.8"},{"seq":147425,"id":"CVE-2026-89704","ts":1789270210862,"field":"severity","old":"none","new":"medium"},{"seq":109180,"id":"CVE-2026-89704","ts":1789183730623,"field":"cvss","old":null,"new":"6.8"},{"seq":109179,"id":"CVE-2026-89704","ts":1789183730623,"field":"severity","old":"none","new":"medium"}]}