Linux Kernel NFS Service Vulnerability Impacting Memory Management
CVE-2026-53399
What is CVE-2026-53399?
A vulnerability in the Linux kernel's NFS service introduces a flaw in memory management related to state identifier handling. When the layout state ID (stid) is allocated and a failure occurs during lease setting, the memory associated with the state ID is freed without properly removing its identifier from the allocated IDR structure. This results in a dangling pointer which can be exploited during subsequent operations that reference the freed memory. Furthermore, mishandling of certain delayed work structures upon failure can lead to uninitialized memory access, compounding potential risks. The corrective measures include restructuring the error handling to ensure proper cleanup and initialization, thus reinforcing data integrity and stability within the NFS service.
Affected Version(s)
Linux c5c707f96fc9a6e5a57ca5baac892673270abe3d
Linux c5c707f96fc9a6e5a57ca5baac892673270abe3d < 8dee7c278f1c2b5bb80e17a6281c3812fc8b0cdd
Linux c5c707f96fc9a6e5a57ca5baac892673270abe3d < 83c2b7797742339bb768f83935f7ca33950db138