๐Ÿ” CVE Alert

CVE-2026-89686

CRITICAL 9.8

nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke nfsd4_alloc_layout_stateid reads fp->fi_deleg_file without holding fi_lock when the parent stateid is a delegation. A concurrent delegation revoke via the laundromat can clear fi_deleg_file under fi_lock, causing nfsd_file_get() to return NULL and triggering the BUG_ON. This race is client-reachable: two NFS clients can trigger it by having one hold a delegation while another opens the same file to force a recall. When the first client doesn't respond to the recall, the laundromat revokes it. A concurrent LAYOUTGET from any client using the delegation stateid hits the race window. Fix this by taking fi_lock around the fi_deleg_file read in the SC_TYPE_DELEG path, matching the locking discipline of the find_any_file() arm, and replacing the BUG_ON with a graceful error return that cleans up the partially-initialized layout stateid.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 13, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new critical vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
c5c707f96fc9a6e5a57ca5baac892673270abe3d < c517f27498757e616d2a8fe6d16caad1fee422e6 c5c707f96fc9a6e5a57ca5baac892673270abe3d < 607a56fea772c1f4f4989d8e255dd4f7192d9604 c5c707f96fc9a6e5a57ca5baac892673270abe3d < 97bda8b4284d90897a1f1922e5082ff9e35d7c7e c5c707f96fc9a6e5a57ca5baac892673270abe3d < ca94ba36172046be6a694a7986f6931e47ed4d51
Linux / Linux
4.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/c517f27498757e616d2a8fe6d16caad1fee422e6 git.kernel.org: https://git.kernel.org/stable/c/607a56fea772c1f4f4989d8e255dd4f7192d9604 git.kernel.org: https://git.kernel.org/stable/c/97bda8b4284d90897a1f1922e5082ff9e35d7c7e git.kernel.org: https://git.kernel.org/stable/c/ca94ba36172046be6a694a7986f6931e47ed4d51