Description
In the Linux kernel, the following vulnerability has been resolved:

SUNRPC: close backchannel before destroying callback service

A backchannel receive can complete a request while the NFS callback
service is being torn down. xprt_complete_bc_request() removes the
request from bc_pa_list, drops bc_alloc_count, marks the request in use,
and then asks xprt_enqueue_bc_request() to hand it to the callback
service.

If teardown has already cleared xprt->bc_serv, xprt_enqueue_bc_request()
currently returns without enqueueing or freeing the committed request.
The xprt_get() taken on entry is leaked as well. If the producer wins
the race before bc_serv is cleared, it can also enqueue onto sv_cb_list
after nfs_callback_down() has stopped the callback threads, leaving the
request linked to a svc_serv that is about to be freed.

Close the producer side before callback threads are stopped. Add
xprt_svc_shutdown_bc() to clear xprt->bc_serv under bc_pa_lock, and call
it on callback shutdown and callback-start failure before stopping the
service threads. Requests that lose the NULL transition in
xprt_enqueue_bc_request() are released through the normal backchannel
free path after balancing bc_slot_count. Finally, drain any remaining
sv_cb_list requests after the callback threads have stopped and before
svc_destroy() frees the service.
Published: 2026-09-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption and potential crash
Action: Patch
AI Analysis

Impact

A race condition in the Linux kernel’s NFS callback subsystem allows a backchannel receive to complete while the callback service is being torn down, service that is about to be freed. This flaw can lead to a leaked reference and a possible use‑after‑free, corrupting kernel memory or causing a crash. The high CVSS score of 9.8 reflects significant denial of service or compromise that may be triggered by controlling NFS traffic, which is a component‑level orchestration defect (CWE‑911).

Affected Systems

All Linux kernel releases incorporate this flaw as it resides in core kernel logic; no specific version range is delineated by the CNA.

Risk and Exploitability

The EPSS score of < 1 % indicates a very low probability of exploitation. The CVSS score of 9.8 signifies extremely high severity, with the potential to cause a kernel crash or denial of service. Attackers would need to influence NFS client traffic while the callback service is shutting down, which may require local or privileged access or a compromised NFS client. The vulnerability is not listed in the CISA KEV catalog and no public exploit has been reported.

Generated by OpenCVE AI on September 15, 2026 at 22:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version that includes the xprt_svc_shutdown_bc() change, ensuring the backchannel is closed before the callback service is destroyed.
  • While waiting for the updated kernel, limit or temporarily unmount NFS shares to prevent new callback traffic from reaching the system.
  • After applying the patch, reboot the system and review system logs such as dmesg for any NFS callback errors to confirm the fix is effective.

Generated by OpenCVE AI on September 15, 2026 at 22:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-911
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: SUNRPC: close backchannel before destroying callback service A backchannel receive can complete a request while the NFS callback service is being torn down. xprt_complete_bc_request() removes the request from bc_pa_list, drops bc_alloc_count, marks the request in use, and then asks xprt_enqueue_bc_request() to hand it to the callback service. If teardown has already cleared xprt->bc_serv, xprt_enqueue_bc_request() currently returns without enqueueing or freeing the committed request. The xprt_get() taken on entry is leaked as well. If the producer wins the race before bc_serv is cleared, it can also enqueue onto sv_cb_list after nfs_callback_down() has stopped the callback threads, leaving the request linked to a svc_serv that is about to be freed. Close the producer side before callback threads are stopped. Add xprt_svc_shutdown_bc() to clear xprt->bc_serv under bc_pa_lock, and call it on callback shutdown and callback-start failure before stopping the service threads. Requests that lose the NULL transition in xprt_enqueue_bc_request() are released through the normal backchannel free path after balancing bc_slot_count. Finally, drain any remaining sv_cb_list requests after the callback threads have stopped and before svc_destroy() frees the service.
Title SUNRPC: close backchannel before destroying callback service
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:30:45.511Z

Reserved: 2026-09-11T19:38:34.722Z

Link: CVE-2026-89546

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:37.960

Modified: 2026-09-13T07:17:16.950

Link: CVE-2026-89546

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:44:21Z

Links: CVE-2026-89546 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:45:07Z

Weaknesses
  • CWE-911

    Improper Update of Reference Count