CVE-2026-53399

Source
https://cve.org/CVERecord?id=CVE-2026-53399
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53399.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-53399
Downstream
Related
Published
2026-07-19T12:02:00Z
Modified
2026-09-05T11:10:53Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
nfsd: release layout stid on setlease failure
Details

In the Linux kernel, the following vulnerability has been resolved:

nfsd: release layout stid on setlease failure

nfs4_alloc_stid() publishes the new stid into cl->cl_stateids via idr_alloc_cyclic() under cl_lock before returning to nfsd4_alloc_layout_stateid(). When nfsd4_layout_setlease() then fails, the error path frees the layout stateid directly with kmem_cache_free() without ever calling idr_remove(), leaving the IDR slot pointing at freed slab memory. Any subsequent IDR walker (states_show, client teardown) dereferences the dangling pointer.

The correct teardown for an IDR-published stid is nfs4_put_stid(), which removes the IDR slot under cl_lock, dispatches sc_free (nfsd4_free_layout_stateid) to release ls->ls_file via nfsd4_close_layout(), and drops the nfs4_file reference in its tail.

A second issue blocks that switch: nfsd4_free_layout_stateid() unconditionally inspects ls->ls_fence_work via delayed_work_pending() under ls_lock, but INIT_DELAYED_WORK(&ls->ls_fence_work, ...) currently runs only after the setlease call. On the setlease-failure path the destructor would touch an uninitialized delayed_work.

nfsd4_alloc_layout_stateid()
  nfs4_alloc_stid()           /* idr_alloc_cyclic under cl_lock */
  nfsd4_layout_setlease()     /* fails */
    nfs4_put_stid()
      nfsd4_free_layout_stateid()
        delayed_work_pending(&ls->ls_fence_work)  /* needs INIT */
        nfsd4_close_layout()  /* nfsd_file_put(ls->ls_file) */
      put_nfs4_file()

Fix by hoisting the ls_fenced / ls_fence_delay / INIT_DELAYED_WORK initialization above the nfsd4_layout_setlease() call, and replace the manual nfsd_file_put + put_nfs4_file + kmem_cache_free cleanup with a single nfs4_put_stid(stp).

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53399.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c5c707f96fc9a6e5a57ca5baac892673270abe3d
Fixed
d788ef40a7517d22c97ab01700e4ae4c611b6f2f
Fixed
2e0a5d6d62600b8c614d1b55e50ef94035d6adf9
Fixed
7bbb7ce74051c8be4b69ff44ce3db370600dae61
Fixed
48a586e382e4db1dbf958d44b63e081df5f8ed04
Fixed
d369e5edfaaf83a448016e2f1da392b2174be801
Fixed
8dee7c278f1c2b5bb80e17a6281c3812fc8b0cdd
Fixed
83c2b7797742339bb768f83935f7ca33950db138
Fixed
30d55c8aabb261bc3f427d6b9aae7ef6206063f9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53399.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.0.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.96
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.39
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53399.json"