---
id: CVE-2026-89684
title: 'kernel: nfsd: fix cpntf publish race in nfs4_init_cp_state (CVE-2026-89684)'
summary: >-
  A flaw was found in the Linux kernel's nfsd component. A remote attacker, by
  sending a specially crafted OFFLOAD_CANCEL request, could exploit a race
  condition during the initialization of copy state notifications. This could
  lead to a den…
severity: high
cvss: 7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'
cvssSource: vendor
cwe: CWE-824
vendor: Red Hat
product: Red Hat Enterprise Linux 9
affected:
  - enterprise_linux 10
  - enterprise_linux 6
  - enterprise_linux 9
  - openshift_container_platform 4
published: '2026-09-11'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T11:06:12+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89684.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89684.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-89684'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2532088'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-89684'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89684'
  - url: >-
      https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89684.mbox
  - url: 'https://git.kernel.org/stable/c/63e18fc65587fd3f7b4c6d70e96d32fc41d82ba3'
  - url: 'https://git.kernel.org/stable/c/6ac469a274e3c7d87fc46ba46d83b95009680407'
  - url: 'https://git.kernel.org/stable/c/8eeca993357a0bc35aaefebfd7462ac7b0a21d9a'
  - url: 'https://git.kernel.org/stable/c/bfeac42d9074e539bacd1898dd8c14b7f5776620'
  - url: 'https://git.kernel.org/stable/c/21d6c5957f5ca97d7352e60f55ea412beb9419f5'
  - url: 'https://git.kernel.org/stable/c/a631a26a8777bb235eabd478bbbaf26a4db750bf'
  - url: 'https://git.kernel.org/stable/c/c7270f62e7a05a2ee68aa2b74262b658a14463bd'
  - url: 'https://git.kernel.org/stable/c/be3a5c1d857b0dcbc11796cea603ef25834f75b2'
tags:
  - csaf
  - vex
  - red-hat
  - cve.org
epss: 0.00508
epssPercentile: 0.42395
scores:
  vendor: 7
  cna: 7.5
ingestedAt: '2026-09-14T15:23:07.450Z'
---

## Overview

A flaw was found in the Linux kernel's nfsd component. A remote attacker, by sending a specially crafted OFFLOAD_CANCEL request, could exploit a race condition during the initialization of copy state notifications. This could lead to a denial of service (DoS) by causing the server to crash.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89684.json)

**kernel: nfsd: fix cpntf publish race in nfs4_init_cp_state** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-21.

Affected:

- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 4

No fix planned:

- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 4

Not affected:

- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat OpenShift Container Platform 4

## Remediation

Out of support scope
