Executive brief
A vulnerability in the Linux kernel's Network File System (NFS) server component could allow a remote user to cause a memory leak. By sending specifically crafted requests that fail during processing, an attacker can cause the server to fail to release memory associated with Access Control Lists (ACLs). Over time, this could exhaust available system memory, potentially leading to a service outage or system instability.
Technical details
A memory leak exists in the Linux kernel's nfsd (NFS server) implementation within the nfsaclsvc_decode_setaclargs() and nfs3svc_decode_setaclargs() functions. These functions call nfs_stream_decode_acl() twice to handle NFS_ACL and NFS_DFACL. If the first call succeeds but the second fails, the decoder returns false, causing the RPC layer to skip the procedure function (pc_func) where cleanup was originally located. Because the default release functions (nfssvc_release_attrstat and nfs3svc_release_fhandle) were unaware of the allocated posix_acl structures, the memory remains leaked for the lifetime of the server. An attacker can trigger this by sending a SETACL request with a valid first ACL but a malformed second ACL. The fix introduces specific release functions that properly free both ACL fields during the pc_release phase, which is executed regardless of decode success or failure.
Affected products
- Linux Linux Kernel versions prior to fixed stable releases (e.g., 6.10, 6.9.4, etc.)
Timeline
- 2026-05-21: disclosed: Initial patch authored by Jeff Layton
- 2026-07-19: advisory: CVE-2026-53397 published in NVD
References
- https://git.kernel.org/stable/c/0853ac544c590880d797b04daa33fcb72b6be0e1
- https://git.kernel.org/stable/c/136b416593f1349cf6f72c8e3d18f0f204ee8545
- https://git.kernel.org/stable/c/1e96239fddcefacf6afe6c498357be68eacbcabc
- https://git.kernel.org/stable/c/887f92ceccf3eacd5f2402db21254d66372fae00
- https://git.kernel.org/stable/c/a5b42c1e4ff2befaa6b96f7cbf32174751eba083
- https://git.kernel.org/stable/c/b2eb1ffd511d1b3c3e21122f97cbbccea411e277
- https://git.kernel.org/stable/c/b94c4be77682aab06d65ca7296149e3bcfb37353