---
id: CVE-2026-89663
title: >-
  kernel: nfsd: revoke copy-notify stateids before dropping their reference
  (CVE-2026-89663)
summary: >-
  A flaw was found in the Linux kernel's Network File System Daemon (nfsd). This
  vulnerability arises from improper handling of "copy-notify stateids" during
  their revocation. When a stateid's reference is dropped without unlinking it,
  the m…
severity: high
cvss: 7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'
cvssSource: vendor
cwe: CWE-825
vendor: Red Hat
product: Red Hat Enterprise Linux 9
affected:
  - enterprise_linux 10
  - enterprise_linux 9
  - openshift_container_platform 4
published: '2026-09-11'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T20:10:36+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89663.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89663.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-89663'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2532231'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-89663'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89663'
  - url: >-
      https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89663.mbox
  - url: 'https://git.kernel.org/stable/c/5f00e0ab4de45d4f9e4bd0883cf2517acf63fc0d'
  - url: 'https://git.kernel.org/stable/c/06a62f6dbc60791f4229c6950b1eec6b18df9af1'
  - url: 'https://git.kernel.org/stable/c/a1fca0f7bbb7b100a39c7ba8dd7922c87c4237a3'
  - url: 'https://git.kernel.org/stable/c/caddbeffab1eaba1d2bcf5ceda35547863466705'
  - url: 'https://git.kernel.org/stable/c/6b8149448cdcb476fba4559d1ecc247efee9971b'
  - url: 'https://git.kernel.org/stable/c/b56d2c5f01cddbeca7d11cce81d97db4ec9a464f'
  - url: 'https://git.kernel.org/stable/c/ff8a3cff02b92b2a82f1a9876038fcf953ae9c25'
  - url: 'https://git.kernel.org/stable/c/3b0c3595db99bb4bebd7c8aa8a36f3c50e411bb7'
tags:
  - csaf
  - vex
  - red-hat
  - cve.org
epss: 0.00455
epssPercentile: 0.38822
scores:
  vendor: 7
  cna: 8.8
ingestedAt: '2026-09-14T15:23:07.450Z'
---

## Overview

A flaw was found in the Linux kernel's Network File System Daemon (nfsd). This vulnerability arises from improper handling of "copy-notify stateids" during their revocation. When a stateid's reference is dropped without unlinking it, the memory can be freed while still in use by a reader, leading to a use-after-free condition. This can cause system instability and potentially allow for unauthorized access.

## Vendor advisories

- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89663.json)

**kernel: nfsd: revoke copy-notify stateids before dropping their reference** — rated Important by Red Hat. Released 2026-09-11, updated 2026-09-18.

Affected:

- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 4

No fix planned:

- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 4

Not affected:

- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat OpenShift Container Platform 4

## Remediation

Affected
