๐Ÿ” CVE Alert

CVE-2026-90104

UNKNOWN 0.0

NFSv4.1: zero referring call lists before decoding

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: NFSv4.1: zero referring call lists before decoding decode_cb_sequence_args() allocates csa_rclists with kmalloc_objs(), so each referring_call_list starts uninitialized. decode_rc_list() assigns rcl_refcalls only when rcl_nrefcalls is nonzero. A valid list with zero referring calls therefore leaves the pointer uninitialized, and nfs4_callback_sequence() later passes stale slab contents to kfree(). Allocate csa_rclists with kzalloc_objs() so every rcl_refcalls member is NULL from the beginning, including valid empty referring call lists.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
4aece6a19cf7f474f15eb861ba74db4479884ce3 < f31f3c042e024aef437cda42f0424ae8d4594b6c 4aece6a19cf7f474f15eb861ba74db4479884ce3 < 8fa4804fe62ca4155a2d8fc2789d630376cbf2fc
Linux / Linux
2.6.31

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/f31f3c042e024aef437cda42f0424ae8d4594b6c git.kernel.org: https://git.kernel.org/stable/c/8fa4804fe62ca4155a2d8fc2789d630376cbf2fc