Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-89686

nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke
Back to all
CVE

CVE-2026-89686

nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke

In the Linux kernel, the following vulnerability has been resolved:

nfsd: fix BUGON in nfsd4alloclayoutstateid on racing delegation revoke

nfsd4alloclayoutstateid reads fp->fideleg_file without holding

fi_lock when the parent stateid is a delegation. A concurrent delegation

revoke via the laundromat can clear fidelegfile under fi_lock, causing

nfsdfileget() to return NULL and triggering the BUG_ON.

This race is client-reachable: two NFS clients can trigger it by having

one hold a delegation while another opens the same file to force a

recall. When the first client doesn't respond to the recall, the

laundromat revokes it. A concurrent LAYOUTGET from any client using the

delegation stateid hits the race window.

Fix this by taking filock around the fideleg_file read in the

SCTYPEDELEG path, matching the locking discipline of the

findanyfile() arm, and replacing the BUG_ON with a graceful error

return that cleans up the partially-initialized layout stateid.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/607a56fea772c1f4f4989d8e255dd4f7192d9604, https://git.kernel.org/stable/c/97bda8b4284d90897a1f1922e5082ff9e35d7c7e, https://git.kernel.org/stable/c/c517f27498757e616d2a8fe6d16caad1fee422e6, https://git.kernel.org/stable/c/ca94ba36172046be6a694a7986f6931e47ed4d51, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89686.json, https://nvd.nist.gov/vuln/detail/CVE-2026-89686, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00663%
EPSS Percentile
0.5015%
Introduced Version
c5c707f96fc9a6e5a57ca5baac892673270abe3d,4.0.0,6.13.0,6.19.0,0
Fix Available
ca94ba36172046be6a694a7986f6931e47ed4d51,6.12.109,6.18.50,7.2.4,6.12.111-1~deb12u1,6.12.111-1,0:6.12.0-207.111.5.1.el10uek,0:6.12.0-207.111.5.1.el9uek

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading