CVE-2026-89681
In the Linux kernel, the following vulnerability has been resolved:
nfsd: fix layout fence worker double-reference race
The workqueue core clears WORKSTRUCTPENDING before the callback
is invoked, so delayedworkpending() in lmbreakertimedout() can
return false while the fence worker is already running. This lets
the breaker take a duplicate sc_count reference and schedule a new
worker that coalesces with the in-progress one. The extra reference
is never put, leaking the layout stateid.
Replace the racy delayedworkpending() check with an
lsfenceinflight boolean set atomically with
refcountincnotzero() under lslock, and cleared under ls_lock
before the final nfs4putstid() on the dispose path; the retry
path intentionally retains it. Remove the self-rearm
moddelayedwork() at the top of the worker.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/8580571227451384399b3fa53fcde19848c48e5a, https://git.kernel.org/stable/c/a278d361e0e8f242211891193d56483a7a9f47a8, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89681.json, https://nvd.nist.gov/vuln/detail/CVE-2026-89681, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git