SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-63800

CRITICAL · CVSS 9.8 EPSS 0.50%

Source: NVD + CISA KEV + EPSS · Published 2026-07-19 · Last synced 2026-08-18

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's pNFS implementation, specifically in the `pnfs_update_layout()` function, where a use-after-free condition can occur due to improper ordering of function calls. This flaw can lead to potential memory corruption, allowing attackers to execute arbitrary code or crash the system. Organizations using Linux systems with pNFS enabled should prioritize patching this critical vulnerability to mitigate the risk of exploitation.

CVE
CVE-2026-63800
Severity
CRITICAL
CVSS
9.8
EPSS
0.50%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: pNFS: Fix use-after-free in pnfs_update_layout() When hitting the NFS_LAYOUT_RETURN branch in pnfs_update_layout(), the code calls pnfs_prepare_to_retry_layoutget(lo). If it succeeds, pnfs_put_layout_hdr(lo) is called before trace_pnfs_update_layout(), which still references 'lo'. This results in a use-after-free when the tracepoint accesses lo's fields. Fix this by moving the tracepoint call before pnfs_put_layout_hdr(lo).

Related CVEs

Other vulnerabilities affecting the same vendor(s)