CVE-2026-53394
HIGH
7.5
CVSS 3.1
Description
In the Linux kernel, the following vulnerability has been resolved:
nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race
When find_or_alloc_open_stateowner() encounters an unconfirmed owner, it
calls release_openowner() and sets oo = NULL. Control then falls through
past the `if (oo)` guard -- which would have freed any pre-allocated
`new` -- and unconditionally executes `new = alloc_stateowner(...)`. If
`new` was already allocated on a prior iteration, the pointer is
silently overwritten and the previous allocation (slab object + owner
name buffer) is leaked.
This requires a race: two NFSv4.0 OPEN threads with the same owner
string, where a concurrent thread inserts a new unconfirmed owner into
the hash between retry iterations. The window is narrow but repeatable
under adversarial conditions.
Fix by adding `goto retry` after `oo = NULL` so the already-allocated
`new` is reused on the next iteration rather than overwritten.
Metadata
Severity & Metrics
7.5
HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products (2)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Linux | Linux | — | 23df17788c6212809848f836b10c4f85b16843a5 < c9aefb2b5f11337c9202c5bd0c45d71198449718, 23df17788c6212809848f836b10c4f85b16843a5 < 017a6150106b054cc84d1b0582d97bd3a74d4281, 23df17788c6212809848f836b10c4f85b16843a5 < a10bf67fe06469a71a401f72f328237345d553c0, 23df17788c6212809848f836b10c4f85b16843a5 < 57aee7a35bb12753057c5b65d72d1f46c0e95b07 |
| Linux | Linux | — | 6.10, 0 < 6.10, 6.12.95 ≤ 6.12.*, 6.18.38 ≤ 6.18.* … |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 7.5 | HIGH | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
References (4)