DEBIAN-CVE-2026-89686
In the Linux kernel, the following vulnerability has been resolved: nfsd: fix BUGON in nfsd4alloclayoutstateid on racing delegation revoke nfsd4alloclayoutstateid reads fp->fidelegfile without holding filock when the parent stateid is a delegation. A concurrent delegation revoke via the laundromat can clear fidelegfile under filock, causing nfsdfileget() to return NULL and triggering the BUGON. This race is client-reachable: two NFS clients can trigger it by having one hold a delegation while another opens the same file to force a recall. When the first client doesn't respond to the recall, the laundromat revokes it. A concurrent LAYOUTGET from any client using the delegation stateid hits the race window. Fix this by taking filock around the fidelegfile read in the SCTYPEDELEG path, matching the locking discipline of the findanyfile() arm, and replacing the BUGON with a graceful error return that cleans up the partially-initialized layout stateid.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://security-tracker.debian.org/tracker/CVE-2026-89686