Answer in brief
CVE-2026-89686 records a Unknown severity vulnerability in nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=c5c707f96fc9a6e5a57ca5baac892673270abe3d <c517f27498757e616d2a8fe6d16caad1fee422e6 || >=c5c707f96fc9a6e5a57ca5baac892673270abe3d <607a56fea772c1f4f4989d8e255dd4f7192d9604 || >=c5c707f96fc9a6e5a57ca5baac892673270abe3d <97bda8b4284d90897a1f1922e5082ff9e35d7c7e || >=c5c707f96fc9a6e5a57ca5baac892673270abe3d <ca94ba36172046be6a694a7986f6931e47ed4d51 | c517f27498757e616d2a8fe6d16caad1fee422e6, 607a56fea772c1f4f4989d8e255dd4f7192d9604, 97bda8b4284d90897a1f1922e5082ff9e35d7c7e, ca94ba36172046be6a694a7986f6931e47ed4d51 |
| Linux/Linuxgeneric | 4.0 | Not reported |
Published upstream
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 11, 2026
In the Linux kernel, the following vulnerability has been resolved: nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke nfsd4_alloc_layout_stateid reads fp->fi_deleg_file without holding fi_lock when the parent stateid is a delegation. A concurrent delegation revoke via the laundromat can clear fi_deleg_file under fi_lock, causing nfsd_file_get() to return NULL and triggering the BUG_ON. This race is client-reachable: two NFS clients can trigger it by having one hold a delegation while another opens the same file to force a recall. When the first client doesn't respond to the recall, the laundromat revokes it. A concurrent LAYOUTGET from any client using the delegation stateid hits the race window. Fix this by taking fi_lock around the fi_deleg_file read in the SC_TYPE_DELEG path, matching the locking discipline of the find_any_file() arm, and replacing the BUG_ON with a graceful error return that cleans up the partially-initialized layout stateid.
Quoted source text, attributed separately from HOL analysis.