SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-53394

HIGH · CVSS 7.5 EPSS 0.49%

Source: NVD + CISA KEV + EPSS · Published 2026-07-19 · Last synced 2026-08-18

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's NFSv4.0 implementation, specifically in the handling of open state owners during concurrent operations. An attacker can exploit a race condition to leak memory by causing the system to overwrite a previously allocated object without freeing it, potentially leading to resource exhaustion or information disclosure. Organizations using Linux systems with NFSv4.0 should prioritize applying the fix to mitigate the risk of exploitation.

CVE
CVE-2026-53394
Severity
HIGH
CVSS
7.5
EPSS
0.49%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race When find_or_alloc_open_stateowner() encounters an unconfirmed owner, it calls release_openowner() and sets oo = NULL. Control then falls through past the `if (oo)` guard -- which would have freed any pre-allocated `new` -- and unconditionally executes `new = alloc_stateowner(...)`. If `new` was already allocated on a prior iteration, the pointer is silently overwritten and the previous allocation (slab object + owner name buffer) is leaked. This requires a race: two NFSv4.0 OPEN threads with the same owner string, where a concurrent thread inserts a new unconfirmed owner into the hash between retry iterations. The window is narrow but repeatable under adversarial conditions. Fix by adding `goto retry` after `oo = NULL` so the already-allocated `new` is reused on the next iteration rather than overwritten.

Related CVEs

Other vulnerabilities affecting the same vendor(s)