Executive brief
A vulnerability in the Linux kernel's NFSv4 implementation could allow a remote attacker to crash the system. The issue occurs when the system processes a specially crafted network file system (NFS) layout, leading to a kernel panic. This could result in a complete service outage for affected servers.
Technical details
A null pointer dereference vulnerability exists in the NFSv4 flexfiles layout driver within the Linux kernel. The function ff_layout_alloc_lseg() decodes a filehandle-version array count from a flexfiles layout body without verifying if the count is zero. When a zero count is provided, kzalloc_objs() returns ZERO_SIZE_PTR, which is subsequently dereferenced in ff_layout_encode_ff_layoutupdate(), leading to a kernel panic (oops). An attacker capable of sending malformed flexfiles layouts to a client can trigger this denial-of-service condition. The issue has been resolved by adding a check to reject layouts with a zero fh_count.
Affected products
- Linux Linux Kernel 4.0 to 7.1.3
Timeline
- 2026-07-19: disclosed
- 2026-07-19: advisory