OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-90104

CRITICAL · CVSS 9.8 EPSS 0.55%

Source: NVD + CISA KEV + EPSS · Published 2026-09-17 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's NFSv4.1 implementation, where uninitialized memory in referring call lists can lead to the use of stale data when freeing memory. This flaw could potentially allow an attacker to exploit the system by manipulating memory management, leading to undefined behavior or crashes. Organizations using Linux kernel versions with NFSv4.1 should prioritize patching this vulnerability to mitigate potential risks associated with memory corruption.

CVE
CVE-2026-90104
Severity
CRITICAL
CVSS
9.8
EPSS
0.55%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: NFSv4.1: zero referring call lists before decoding decode_cb_sequence_args() allocates csa_rclists with kmalloc_objs(), so each referring_call_list starts uninitialized. decode_rc_list() assigns rcl_refcalls only when rcl_nrefcalls is nonzero. A valid list with zero referring calls therefore leaves the pointer uninitialized, and nfs4_callback_sequence() later passes stale slab contents to kfree(). Allocate csa_rclists with kzalloc_objs() so every rcl_refcalls member is NULL from the beginning, including valid empty referring call lists.