DEBIAN-CVE-2026-89681
In the Linux kernel, the following vulnerability has been resolved: nfsd: fix layout fence worker double-reference race The workqueue core clears WORKSTRUCTPENDING before the callback is invoked, so delayedworkpending() in lmbreakertimedout() can return false while the fence worker is already running. This lets the breaker take a duplicate sccount reference and schedule a new worker that coalesces with the in-progress one. The extra reference is never put, leaking the layout stateid. Replace the racy delayedworkpending() check with an lsfenceinflight boolean set atomically with refcountincnotzero() under lslock, and cleared under lslock before the final nfs4putstid() on the dispose path; the retry path intentionally retains it. Remove the self-rearm moddelayedwork() at the top of the worker.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://security-tracker.debian.org/tracker/CVE-2026-89681