* CVE-2026-89692: nfsd: clear CALLBACK_RUNNING on failed delegation recall queue
@ 2026-09-11 19:46 Greg Kroah-Hartman
0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-11 19:46 UTC (permalink / raw)
To: linux-cve-announce; +Cc: Greg Kroah-Hartman
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
nfsd: clear CALLBACK_RUNNING on failed delegation recall queue
nfsd_break_one_deleg() sets NFSD4_CALLBACK_RUNNING via test_and_set_bit
at entry to serialize recall work, then calls nfsd4_run_cb() to queue
the recall. When the queue attempt fails the refcount bump is undone,
but the RUNNING bit is left set. The only site that clears the bit is
nfsd41_destroy_cb() (fs/nfsd/nfs4callback.c), which runs from the
workqueue and is therefore unreachable when nothing was queued.
The bit becomes a permanent latch on dp->dl_recall.cb_flags: every
subsequent break_lease() on the same delegation hits the early-return
guard in nfsd_break_one_deleg() and silently skips the recall, so the
delegation is never broken and the conflicting open or lock stalls.
Fix by clearing NFSD4_CALLBACK_RUNNING on the !queued branch alongside
the refcount_dec.
The Linux kernel CVE team has assigned CVE-2026-89692 to this issue.
Affected and fixed versions
===========================
Issue introduced in 6.15 with commit 1054e8ffc5c492f341bdf1888b882f1d163dd3d8 and fixed in 6.18.50 with commit b137930ee52e3ef38915a3511d4c070463b63a32
Issue introduced in 6.15 with commit 1054e8ffc5c492f341bdf1888b882f1d163dd3d8 and fixed in 7.2.4 with commit cb2d0c4d1b3d301d042ed61365eaa8cb0141a254
Issue introduced in 6.15 with commit 1054e8ffc5c492f341bdf1888b882f1d163dd3d8 and fixed in 7.3-rc1 with commit b036727d334b1b7cd4c1f1fba3b59ba93a6bbe96
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-89692
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
fs/nfsd/nfs4state.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/b137930ee52e3ef38915a3511d4c070463b63a32
https://git.kernel.org/stable/c/cb2d0c4d1b3d301d042ed61365eaa8cb0141a254
https://git.kernel.org/stable/c/b036727d334b1b7cd4c1f1fba3b59ba93a6bbe96
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-09-11 20:02 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-11 19:46 CVE-2026-89692: nfsd: clear CALLBACK_RUNNING on failed delegation recall queue Greg Kroah-Hartman
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.