๐Ÿ” CVE Alert

CVE-2026-53398

UNKNOWN 0.0

NFSD: Fix SECINFO_NO_NAME decode error cleanup

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix SECINFO_NO_NAME decode error cleanup nfsd4_decode_secinfo_no_name() currently initializes sin_exp after decoding sin_style. If the XDR stream is truncated, the decoder returns nfserr_bad_xdr before sin_exp is initialized. Since commit 3fdc54646234 ("NFSD: Reduce amount of struct nfsd4_compoundargs that needs clearing"), the inline iops array is not cleared between RPC calls. A failed SECINFO_NO_NAME decode can therefore leave sin_exp holding stale union contents from a previous operation. The error response path still invokes nfsd4_secinfo_no_name_release(), which calls exp_put() on a non-NULL sin_exp. Initialize sin_exp before the first failable decode step, matching nfsd4_decode_secinfo().

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 19, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
5e76b25d7cc82c148d391c0c43b884e6427cb302 < 8836405abdc53ca3dd5fc68b2cf6f8f012fad011 07b68ff5c71cf4ed5443016d8eb116863c0a4d88 < 49de5d31dd8fdebf78bdeaf196b0ca5cd5c75439 3fdc546462348b8a497c72bc894e0cde9f10fc40 < 5ec37edcb534f3fc92304be236d37f08e6545585 3fdc546462348b8a497c72bc894e0cde9f10fc40 < 1e04be34cafae119e82bcaccd6d28a20f72a3647 3fdc546462348b8a497c72bc894e0cde9f10fc40 < 161d1aaeb04d620d3692639700512bb5038c1e10 3fdc546462348b8a497c72bc894e0cde9f10fc40 < c8a24effd96d4779e2ad779654682304491c55a5 3fdc546462348b8a497c72bc894e0cde9f10fc40 < 46eb17d45be69d28c7a23ea03283b207426a8232 3fdc546462348b8a497c72bc894e0cde9f10fc40 < 9e18e83b8846a5c3fe13fc8a464b4865d33996c6 5.10.220 < 5.10.260 5.15.154 < 5.15.211
Linux / Linux
6.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/8836405abdc53ca3dd5fc68b2cf6f8f012fad011 git.kernel.org: https://git.kernel.org/stable/c/49de5d31dd8fdebf78bdeaf196b0ca5cd5c75439 git.kernel.org: https://git.kernel.org/stable/c/5ec37edcb534f3fc92304be236d37f08e6545585 git.kernel.org: https://git.kernel.org/stable/c/1e04be34cafae119e82bcaccd6d28a20f72a3647 git.kernel.org: https://git.kernel.org/stable/c/161d1aaeb04d620d3692639700512bb5038c1e10 git.kernel.org: https://git.kernel.org/stable/c/c8a24effd96d4779e2ad779654682304491c55a5 git.kernel.org: https://git.kernel.org/stable/c/46eb17d45be69d28c7a23ea03283b207426a8232 git.kernel.org: https://git.kernel.org/stable/c/9e18e83b8846a5c3fe13fc8a464b4865d33996c6