Description
In the Linux kernel, the following vulnerability has been resolved:

nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke

nfsd4_alloc_layout_stateid reads fp->fi_deleg_file without holding
fi_lock when the parent stateid is a delegation. A concurrent delegation
revoke via the laundromat can clear fi_deleg_file under fi_lock, causing
nfsd_file_get() to return NULL and triggering the BUG_ON.

This race is client-reachable: two NFS clients can trigger it by having
one hold a delegation while another opens the same file to force a
recall. When the first client doesn't respond to the recall, the
laundromat revokes it. A concurrent LAYOUTGET from any client using the
delegation stateid hits the race window.

Fix this by taking fi_lock around the fi_deleg_file read in the
SC_TYPE_DELEG path, matching the locking discipline of the
find_any_file() arm, and replacing the BUG_ON with a graceful error
return that cleans up the partially-initialized layout stateid.
Published: 2026-09-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

The flaw is a NULL pointer dereference (CWE-476) in the Linux NFS server’s layout state ID allocation code. In nfsd4_alloc_layout_stateid the field fi_deleg_file is read without holding fi_lock when the parent stateid represents a delegation. A concurrent delegation revoke performed by the kernel laundromat can clear fi_deleg_file while under fi_lock, causing nfsd_file_get() to return NULL and triggering a BUG_ON. The BUG_ON on the null pointer dereference crashes the kernel, resulting in a denial of service for the NFS service.

Affected Systems

Linux distributions running a kernel that does not yet contain the commit that locks the fi_deleg_file read and replaces the BUG_ON are vulnerable. The issue is limited to the NFS server component; only servers that enable NFSv4 LAYOUTGET and delegations are affected. No specific kernel release numbers are listed in the advisory, so any kernel version prior to the patch is considered vulnerable.

Risk and Exploitability

The CVSS score of 9.8 marks this as a critical vulnerability, while the EPSS score of <1% indicates a low likelihood of exploitation at the time. The flaw is not listed in CISA’s KEV catalog. The attack vector is client‑reachable: an attacker must have access to two NFS clients – one that holds a delegation and another that opens the same file to force a recall – in order to create the race condition that leads to a kernel crash.

Generated by OpenCVE AI on September 15, 2026 at 20:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the nfsd4_alloc_layout_stateid fix, which adds the missing lock and removes the BUG_ON.
  • If an immediate kernel upgrade is not possible, disable NFS delegations (CONFIG_NFS_DELEGACIES) or configure NFS export options to disallow delegations or the LAYOUTGET operation to eliminate the race condition.
  • Restart the NFS server after applying the patch or configuration change to ensure the updated code or settings take effect.

Generated by OpenCVE AI on September 15, 2026 at 20:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke nfsd4_alloc_layout_stateid reads fp->fi_deleg_file without holding fi_lock when the parent stateid is a delegation. A concurrent delegation revoke via the laundromat can clear fi_deleg_file under fi_lock, causing nfsd_file_get() to return NULL and triggering the BUG_ON. This race is client-reachable: two NFS clients can trigger it by having one hold a delegation while another opens the same file to force a recall. When the first client doesn't respond to the recall, the laundromat revokes it. A concurrent LAYOUTGET from any client using the delegation stateid hits the race window. Fix this by taking fi_lock around the fi_deleg_file read in the SC_TYPE_DELEG path, matching the locking discipline of the find_any_file() arm, and replacing the BUG_ON with a graceful error return that cleans up the partially-initialized layout stateid.
Title nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:33:09.795Z

Reserved: 2026-09-11T19:38:34.749Z

Link: CVE-2026-89686

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:55.533

Modified: 2026-09-13T07:17:34.367

Link: CVE-2026-89686

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:46:07Z

Links: CVE-2026-89686 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:45:20Z

Weaknesses