CVE-2026-89546
In the Linux kernel, the following vulnerability has been resolved:
SUNRPC: close backchannel before destroying callback service
A backchannel receive can complete a request while the NFS callback
service is being torn down. xprtcompletebc_request() removes the
request from bcpalist, drops bcalloccount, marks the request in use,
and then asks xprtenqueuebc_request() to hand it to the callback
service.
If teardown has already cleared xprt->bcserv, xprtenqueuebcrequest()
currently returns without enqueueing or freeing the committed request.
The xprt_get() taken on entry is leaked as well. If the producer wins
the race before bcserv is cleared, it can also enqueue onto svcb_list
after nfscallbackdown() has stopped the callback threads, leaving the
request linked to a svc_serv that is about to be freed.
Close the producer side before callback threads are stopped. Add
xprtsvcshutdownbc() to clear xprt->bcserv under bcpalock, and call
it on callback shutdown and callback-start failure before stopping the
service threads. Requests that lose the NULL transition in
xprtenqueuebc_request() are released through the normal backchannel
free path after balancing bcslotcount. Finally, drain any remaining
svcblist requests after the callback threads have stopped and before
svc_destroy() frees the service.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/3674f780f47d2906b5a0f7199b66973067bdfeca, https://git.kernel.org/stable/c/6debde9e3e6ae21dcca75837b4247b13ca4ea2b8, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89546.json, https://nvd.nist.gov/vuln/detail/CVE-2026-89546, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git