Junglewise Threat Intelligence

CVE-2026-53399: Linux Kernel nfsd use-after-free in nfsd4_alloc_layout_stateid

CVE-2026-53399 · Severity: info · CVSS 5.5 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Network File System (NFS) server component. When the system fails to set a specific type of file lock (a lease) during layout allocation, it incorrectly cleans up internal memory structures. This can lead to a system crash or instability when the kernel later tries to access that memory, potentially impacting the availability of the file server.

Technical details

A use-after-free vulnerability exists in fs/nfsd/nfs4layouts.c within the Linux kernel. The function nfs4_alloc_stid() publishes a new stateid into the client stateid IDR before returning to nfsd4_alloc_layout_stateid(). If a subsequent call to nfsd4_layout_setlease() fails, the error path incorrectly frees the layout stateid using kmem_cache_free() without removing the corresponding entry from the IDR. This leaves a dangling pointer in the IDR table that can be dereferenced by subsequent IDR walkers, such as during client teardown or state inspection. Additionally, the fix addresses an uninitialized delayed_work structure (ls_fence_work) that could be accessed during the corrected teardown path. The issue has been resolved by ensuring proper IDR removal via nfs4_put_stid() and reordering initialization.

Affected products

  • Linux Linux Kernel 4.0 to 6.13

Timeline

  • 2026-05-18: other: Patch authored
  • 2026-07-19: disclosed: CVE published

References

Related threats