NFSD: Fix SECINFO_NO_NAME decode error cleanup

Summary

CVECVE-2026-53398
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-07-19 12:16:50 UTC
Updated2026-07-20 15:16:42 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: NFSD: Fix SECINFO_NO_NAME decode error cleanup nfsd4_decode_secinfo_no_name() currently initializes sin_exp after decoding sin_style. If the XDR stream is truncated, the decoder returns nfserr_bad_xdr before sin_exp is initialized. Since commit 3fdc54646234 ("NFSD: Reduce amount of struct nfsd4_compoundargs that needs clearing"), the inline iops array is not cleared between RPC calls. A failed SECINFO_NO_NAME decode can therefore leave sin_exp holding stale union contents from a previous operation. The error response path still invokes nfsd4_secinfo_no_name_release(), which calls exp_put() on a non-NULL sin_exp. Initialize sin_exp before the first failable decode step, matching nfsd4_decode_secinfo().

Risk And Classification

Primary CVSS: v3.1 9.8 CRITICAL from 416baaa9-dc9f-4396-8d5f-8c081fb06d67

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS: 0.001770000 probability, percentile 0.074150000 (date 2026-07-20)


VersionSourceTypeScoreSeverityVector
3.1416baaa9-dc9f-4396-8d5f-8c081fb06d67Secondary9.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
3.1CNADECLARED9.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v3.1 Breakdown

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 5e76b25d7cc82c148d391c0c43b884e6427cb302 8836405abdc53ca3dd5fc68b2cf6f8f012fad011 git Not specified
CNA Linux Linux affected 07b68ff5c71cf4ed5443016d8eb116863c0a4d88 49de5d31dd8fdebf78bdeaf196b0ca5cd5c75439 git Not specified
CNA Linux Linux affected 3fdc546462348b8a497c72bc894e0cde9f10fc40 5ec37edcb534f3fc92304be236d37f08e6545585 git Not specified
CNA Linux Linux affected 3fdc546462348b8a497c72bc894e0cde9f10fc40 1e04be34cafae119e82bcaccd6d28a20f72a3647 git Not specified
CNA Linux Linux affected 3fdc546462348b8a497c72bc894e0cde9f10fc40 161d1aaeb04d620d3692639700512bb5038c1e10 git Not specified
CNA Linux Linux affected 3fdc546462348b8a497c72bc894e0cde9f10fc40 c8a24effd96d4779e2ad779654682304491c55a5 git Not specified
CNA Linux Linux affected 3fdc546462348b8a497c72bc894e0cde9f10fc40 46eb17d45be69d28c7a23ea03283b207426a8232 git Not specified
CNA Linux Linux affected 3fdc546462348b8a497c72bc894e0cde9f10fc40 9e18e83b8846a5c3fe13fc8a464b4865d33996c6 git Not specified
CNA Linux Linux affected 5.10.220 5.10.260 semver Not specified
CNA Linux Linux affected 5.15.154 5.15.211 semver Not specified
CNA Linux Linux affected 6.1 Not specified
CNA Linux Linux unaffected 6.1 semver Not specified
CNA Linux Linux unaffected 5.10.260 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.211 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.177 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.144 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.95 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.38 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.3 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2-rc1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/5ec37edcb534f3fc92304be236d37f08e6545585 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/161d1aaeb04d620d3692639700512bb5038c1e10 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/1e04be34cafae119e82bcaccd6d28a20f72a3647 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/46eb17d45be69d28c7a23ea03283b207426a8232 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/9e18e83b8846a5c3fe13fc8a464b4865d33996c6 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/c8a24effd96d4779e2ad779654682304491c55a5 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/8836405abdc53ca3dd5fc68b2cf6f8f012fad011 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/49de5d31dd8fdebf78bdeaf196b0ca5cd5c75439 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report