PT-2026-61099 · Linux · Linux

CVE-2026-53394

·

Published

2026-07-19

·

Updated

2026-07-19

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the Linux kernel, the following vulnerability has been resolved:
nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race
When find or alloc open stateowner() encounters an unconfirmed owner, it calls release openowner() and sets oo = NULL. Control then falls through past the if (oo) guard -- which would have freed any pre-allocated new -- and unconditionally executes new = alloc stateowner(...). If new was already allocated on a prior iteration, the pointer is silently overwritten and the previous allocation (slab object + owner name buffer) is leaked.
This requires a race: two NFSv4.0 OPEN threads with the same owner string, where a concurrent thread inserts a new unconfirmed owner into the hash between retry iterations. The window is narrow but repeatable under adversarial conditions.
Fix by adding goto retry after oo = NULL so the already-allocated new is reused on the next iteration rather than overwritten.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-53394

Affected Products

Linux