# CVE-2026-89686

## Summary

- **CVE ID:** CVE-2026-89686
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 13, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke

nfsd4_alloc_layout_stateid reads fp->fi_deleg_file without holding
fi_lock when the parent stateid is a delegation. A concurrent delegation
revoke via the laundromat can clear fi_deleg_file under fi_lock, causing
nfsd_file_get() to return NULL and triggering the BUG_ON.

This race is client-reachable: two NFS clients can trigger it by having
one hold a delegation while another opens the same file to force a
recall. When the first client doesn't respond to the recall, the
laundromat revokes it. A concurrent LAYOUTGET from any client using the
delegation stateid hits the race window.

Fix this by taking fi_lock around the fi_deleg_file read in the
SC_TYPE_DELEG path, matching the locking discipline of the
find_any_file() arm, and replacing the BUG_ON with a graceful error
return that cleans up the partially-initialized layout stateid.

## Affected Products

- Linux — Linux (c5c707f96fc9a6e5a57ca5baac892673270abe3d)
- Linux — Linux (4.0)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)

## References

- [CNA](https://git.kernel.org/stable/c/c517f27498757e616d2a8fe6d16caad1fee422e6)
- [CNA](https://git.kernel.org/stable/c/607a56fea772c1f4f4989d8e255dd4f7192d9604)
- [CNA](https://git.kernel.org/stable/c/97bda8b4284d90897a1f1922e5082ff9e35d7c7e)
- [CNA](https://git.kernel.org/stable/c/ca94ba36172046be6a694a7986f6931e47ed4d51)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.67%
- **EPSS Percentile:** 50.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._