Home / Security / Advisories / NTAP-20261002-0014
NTAP-20261002-0014 — CVE-2026-89669 Linux Kernel Vulnerability in NetApp Products
Published 2026-10-02 · Updated 2026-10-02 · Status: Interim · Exploitation: Public · Severity: CRITICAL 9.8 · ONTAP affected: Yes
Product family: Baseboard management controllers · Active IQ Unified Manager · Brocade SAN firmware · ONTAP · Other NetApp products · NetApp Console / BlueXP · SolidFire / NetApp HCI · SnapCenter | ONTAP-relevant | highest CVSS: 9.8
CVEs in this advisory
- CVE-2026-89669 — CRITICAL · CVSS 9.8 · site index
What the CVE records say
CVE-2026-89669 — In the Linux kernel, the following vulnerability has been resolved: nfsd: initialize copy-notify stateid before publishing it nfsd4_copy_notify() finished initializing the cpntf state after nfs4_alloc_init_cpntf_state() had already linked it into the s2s_cp_stateids IDR and the parent's sc_cp_list, with cs_count == 1 (the membership reference) and none held for the caller. A racing OFFLOAD_CANCEL (crafted cl_id == nn->s2s_cp_cl_id plus the guessable so_id) could reach manage_cpntf_state() and free the entry, turning the caller's subsequent cpn_cnr_stateid read and cp_p_stateid/cp_p_clid writes into use-after-free. The owning clientid was also only recorded after publication, so it could not gate an ownership check in that window. Record cp_p_stateid and cp_p_clid inside nfs4_alloc_init_cpntf_state() before nfs4_init_cp_state() publishes the entry, and return it with an extra reference. The caller reads the stateid under that reference and drops it with nfs4_put_cpntf_state(); on a late error the laundromat reaps the entry.
Impact
Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data or Denial of Service (DoS).
Affected products
- AFF Baseboard Management Controller (BMC) - A700s
- Active IQ Unified Manager for VMware vSphere
- Brocade Fabric Operating System Firmware
- Cloud Volumes ONTAP Mediator
- FAS/AFF BIOS - A900/9500
- FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400
- FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250
- NetApp Console Agent OVA
- NetApp HCI Baseboard Management Controller (BMC) - H610S
- NetApp SolidFire & HCI Management Node
- NetApp SolidFire & HCI Storage Node (Element Software)
- ONTAP Select Deploy administration utility
References
What to do
- Check the affected products listed above against the official advisory's affected-versions table — that is where the exact ONTAP 9 release, ONTAP tool, or management product versions are named.
- If affected and a fixed release exists, plan the upgrade — see the ONTAP upgrade runbook.
- If exploitation is listed as "active", treat remediation as urgent and review exposure (management LIFs, ONTAP S3, SnapMirror endpoints).
- Harden in parallel: security hardening baseline and ransomware protection on ONTAP.
Related reading
- Common ONTAP problems (FAQ) — plain-language symptoms and fixes
- ONTAP security hardening — baseline lockdown guidance
- Ransomware protection on ONTAP — SnapLock, SnapMirror vaulting, Anomaly Detection
- ONTAP error messages index — EMS/WAFL/NFS/SnapMirror messages
- Every NetApp advisory published in 2026