Race condition in Linux kernel - CVE-2026-89686
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a race condition in nfsd4_alloc_layout_stateid when concurrently revoking a delegation and processing a LAYOUTGET request. A remote attacker can send concurrent NFS requests that trigger delegation recall and layout-state allocation to cause a denial of service.
Exploitation requires one NFS client to hold a delegation and fail to respond to its recall while another client opens the same file.