CVE-2026-89686
A race condition in the Linux NFS server can cause a kernel crash when two clients interact with a delegated file. The flaw allows an attacker to trigger a BUG_ON that brings down the system. It has been fixed in a recent kernel update.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel NFS server components, especially nfsd4_alloc_layout_stateid, on any system running an affected kernel version.
Real-world impact
An attacker could force the NFS server to crash, causing a denial of service to all clients that rely on that server.
Why this severity
The CVSS score is high because the flaw can be triggered over the network without authentication, and it results in complete loss of confidentiality, integrity, and availability.
What to do about it
- 01Upgrade the Linux kernel to a version that includes the fix for CVE-2026-89686.
NVD-referenced vendor advisory
Timeline
- Sep 11, 2026 · 2d agoPublishedDisclosed and added to the National Vulnerability Database.
- Sep 13, 2026 · 7h agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.