SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-53392

HIGH · CVSS 7.5 EPSS 0.53%

Source: NVD + CISA KEV + EPSS · Published 2026-07-19 · Last synced 2026-08-18

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's handling of NFSv4 flexfiles, specifically in the `ff_layout_alloc_lseg()` function, which improperly processes a zero filehandle version count, leading to potential null pointer dereferences and kernel panics. This flaw can be exploited by attackers to cause system crashes or instability through malformed flexfiles layouts. Organizations using Linux systems, particularly those relying on NFSv4 for file sharing, should prioritize applying the patch to mitigate the risk of service disruptions.

CVE
CVE-2026-53392
Severity
HIGH
CVSS
7.5
EPSS
0.53%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: NFSv4/flexfiles: reject zero filehandle version count ff_layout_alloc_lseg() decodes the filehandle-version array count from the flexfiles layout body. The value is used as the count for kzalloc_objs(), and the current code only rejects NULL. A zero count yields ZERO_SIZE_PTR, which can be stored in dss_info->fh_versions even though later flexfiles paths assume that at least one filehandle version exists. Reject fh_count == 0 before the allocation, matching the existing zero version_count validation in the flexfiles GETDEVICEINFO parser. A QEMU/KASAN run with a malformed flexfiles layout hit: KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017] RIP: 0010:ff_layout_encode_ff_layoutupdate.isra.0+0x15f/0x750 ff_layout_encode_layoutreturn+0x683/0x970 nfs4_xdr_enc_layoutreturn+0x278/0x3a0 Kernel panic - not syncing: Fatal exception The patched kernel rejects the malformed layout without KASAN/oops/panic, and a valid fh_count=1 regression still opens, reads, and unmounts cleanly.

Related CVEs

Other vulnerabilities affecting the same vendor(s)