{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  SUNRPC: close backchannel before destroying callback service  A backchannel receive can complete a request while the NFS callback service is being torn down.  xprt_complete_bc_request() removes the request from bc_pa_list, drops bc_alloc_count, marks the request in use, and then asks xprt_enqueue_bc_request() to hand it to the callback service.  If teardown has already cleared xprt-\u003ebc_serv, xprt_enqueue_bc_request() currently returns without enqueueing or freeing the committed request. The xprt_get() taken on entry is leaked as well.  If the producer wins the race before bc_serv is cleared, it can also enqueue onto sv_cb_list after nfs_callback_down() has stopped the callback threads, leaving the request linked to a svc_serv that is about to be freed.  Close the producer side before callback threads are stopped.  Add xprt_svc_shutdown_bc() to clear xprt-\u003ebc_serv under bc_pa_lock, and call it on callback shutdown and callback-start failure before stopping the service threads.  Requests that lose the NULL transition in xprt_enqueue_bc_request() are released through the normal backchannel free path after balancing bc_slot_count.  Finally, drain any remaining sv_cb_list requests after the callback threads have stopped and before svc_destroy() frees the service.",
  "id": "DEBIAN-CVE-2026-89546",
  "modified": "2026-09-14T08:47:38.994214346Z",
  "published": "2026-09-11T20:19:37.960Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-89546"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-89546"
  ]
}