Vulnerability in Linux Kernel Affecting NFSD Functionality
CVE-2026-53398

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-53398?

In the Linux kernel, an issue has been identified in the NFSD (Network File System Daemon) related to the SECINFO_NO_NAME decoding process. Specifically, if the XDR (External Data Representation) stream is truncated, an existing operation may leave stale data in a union within the structure. This occurs because the sin_exp variable is not properly initialized before an error response, potentially causing unexpected behaviors when handling decoded information. A fix has been implemented to ensure proper initialization, aligning with best practices for the management of decoding states.

Affected Version(s)

Linux 5e76b25d7cc82c148d391c0c43b884e6427cb302 < 8836405abdc53ca3dd5fc68b2cf6f8f012fad011

Linux 07b68ff5c71cf4ed5443016d8eb116863c0a4d88 < 49de5d31dd8fdebf78bdeaf196b0ca5cd5c75439

Linux 3fdc546462348b8a497c72bc894e0cde9f10fc40 < 5ec37edcb534f3fc92304be236d37f08e6545585

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.