{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89686","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.749Z","datePublished":"2026-09-11T19:46:07.877Z","dateUpdated":"2026-09-13T06:33:09.795Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:33:09.795Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke\n\nnfsd4_alloc_layout_stateid reads fp->fi_deleg_file without holding\nfi_lock when the parent stateid is a delegation. A concurrent delegation\nrevoke via the laundromat can clear fi_deleg_file under fi_lock, causing\nnfsd_file_get() to return NULL and triggering the BUG_ON.\n\nThis race is client-reachable: two NFS clients can trigger it by having\none hold a delegation while another opens the same file to force a\nrecall. When the first client doesn't respond to the recall, the\nlaundromat revokes it. A concurrent LAYOUTGET from any client using the\ndelegation stateid hits the race window.\n\nFix this by taking fi_lock around the fi_deleg_file read in the\nSC_TYPE_DELEG path, matching the locking discipline of the\nfind_any_file() arm, and replacing the BUG_ON with a graceful error\nreturn that cleans up the partially-initialized layout stateid."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - The flaw is in nfsd pNFS LAYOUTGET (nfsd4_alloc_layout_stateid in fs/nfsd/nfs4layouts.c). A remote NFSv4.1 client reaches it over TCP/2049 via nfsd_dispatch to nfsd4_proc_compound to nfsd4_layoutget, so no local access to the NFS server is required.\nAC:L - The attacker controls both sides of the race: one NFS client obtains a delegation while another OPENs the same file to force recall, then the first client withholds CB_RECALL and issues concurrent LAYOUTGET with the delegation stateid as the laundromat runs put_deleg_file. The sequence is retryable and can be timed using FATTR4_LEASE_TIME.\nPR:N - Typical nfsd deployments accept AUTH_SYS/AUTH_NULL without cryptographic authentication. Any host allowed by the export ACL can EXCHANGE_ID/CREATE_SESSION, OPEN to receive a delegation, and LAYOUTGET; no local account or capability on the NFS server is required.\nUI:N - The attacking NFS clients drive the OPEN, recall, and LAYOUTGET compounds themselves against an already-running nfsd export. No victim user action such as mounting a filesystem or opening a file on the server is required.\nS:U - The unlocked fi_deleg_file load and resulting BUG_ON or nfsd_file use-after-free occur in kernel nfsd state on the NFS server host. Impact stays in that kernel security authority and does not cross a VM, IOMMU, or sandbox boundary.\nC:H - put_deleg_file may drop the last nfsd_file ref and call_rcu-free it (KMEM_CACHE flags 0, not SLAB_TYPESAFE_BY_RCU) while LAYOUTGET still calls nfsd_file_get on the stale pointer. After slab reuse the layout stateid's nf_file can be leveraged for kernel information disclosure.\nI:H - The same stale nfsd_file pointer is used for refcount_inc_not_zero and later nfsd4_layout_setlease/kernel_setlease on nf_file. Heap reuse of the nfsd_file slab enables an arbitrary write or control-flow hijack per kernel UAF scoring guidance.\nA:H - When nfsd_file_get returns NULL the original code hits BUG_ON(!ls->ls_file), oopsing or panicking the nfsd thread. Even without that assertion, use-after-free of nfsd_file crashes nfsd, and the attacker can repeat LAYOUTGET to deny NFS service."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfsd/nfs4layouts.c"],"versions":[{"version":"c5c707f96fc9a6e5a57ca5baac892673270abe3d","lessThan":"c517f27498757e616d2a8fe6d16caad1fee422e6","status":"affected","versionType":"git"},{"version":"c5c707f96fc9a6e5a57ca5baac892673270abe3d","lessThan":"607a56fea772c1f4f4989d8e255dd4f7192d9604","status":"affected","versionType":"git"},{"version":"c5c707f96fc9a6e5a57ca5baac892673270abe3d","lessThan":"97bda8b4284d90897a1f1922e5082ff9e35d7c7e","status":"affected","versionType":"git"},{"version":"c5c707f96fc9a6e5a57ca5baac892673270abe3d","lessThan":"ca94ba36172046be6a694a7986f6931e47ed4d51","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfsd/nfs4layouts.c"],"versions":[{"version":"4.0","status":"affected"},{"version":"0","lessThan":"4.0","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/c517f27498757e616d2a8fe6d16caad1fee422e6"},{"url":"https://git.kernel.org/stable/c/607a56fea772c1f4f4989d8e255dd4f7192d9604"},{"url":"https://git.kernel.org/stable/c/97bda8b4284d90897a1f1922e5082ff9e35d7c7e"},{"url":"https://git.kernel.org/stable/c/ca94ba36172046be6a694a7986f6931e47ed4d51"}],"title":"nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke","x_generator":{"engine":"bippy-1.2.0"}}}}