Description
In the Linux kernel, the following vulnerability has been resolved:

NFSv4/pnfs: key the data server cache on the NFS version

nfs4_pnfs_ds_add() keys the per-net data server cache on the multipath
address set alone, and struct nfs4_pnfs_ds records no version. That
suffices for the files layout driver, which always connects with version
4, but flexfiles takes its version tuple from GETDEVICEINFO per device,
and one address can legitimately serve both NFSv3 and NFSv4.

Two deviceids on one address with different ds_versions[0].version
therefore share a single nfs4_pnfs_ds, and whichever mirror connects
first pins ds_clp to its own version. The other one is handed that
client anyway, so it selects rpc_call_ops for a version the connection
does not speak, and the mismatched sequence-slot handling dereferences
NULL.

Add the version to the cache key so the two cannot alias, giving each
version its own nfs4_pnfs_ds and connection while both mirrors stay
usable. Only the major version is compared, since that is what selects
rpc_call_ops and rpc_ops; v4.0 and v4.1 keep sharing a client. The files
layout driver passes the 4 it already hardcodes at connect time.
Published: 2026-09-17
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability lies in the NFSv4/pnfs implementation of the Linux kernel. When a data server cache is keyed solely on the multipath address set, devices that share that address but use different NFS protocol versions can map to the same cache entry. A client that first connects with, for example, NFSv3 pins the cache to that version, while a later client connecting with NFSv4 receives a cache referencing a server that does not speak its protocol, causing rpc_call_ops to be invoked for the wrong NFS version. This mismatch leads to a dereference of a NULL pointer during sequence‑slot handling, causing an immediate kernel crash.

Affected Systems

Affected systems are all installations of the Linux kernel that include the NFSv4/pnfs module and use multipath data server caching. The issue has no explicit version bounds in the advisory, indicating that it could impact any kernel revision prior to the fix. Kernel commits that address the flaw are present in the repository references provided, so any system running a kernel older than those commits is potentially vulnerable.

Risk and Exploitability

Based on the description, it is inferred that the attack vector is an NFS client connection to a server that uses multiple data servers with different protocol versions. The EPSS score is less than 1 percent and the vulnerability is not listed in CISA's KEV catalog, indicating a low likelihood of exploitation in the wild. The CVSS score of 7.5 indicates high severity. Because the flaw is triggered by a straightforward NFS client connection, a remote attacker who can inject traffic to an NFS server can cause a denial‑of‑service. Updating the kernel to incorporate the fix removes the vulnerability entirely.

Generated by OpenCVE AI on September 20, 2026 at 03:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that introduces versioned cache keys for the NFSv4/pnfs data server module.
  • Restrict NFS client connectivity to trusted networks or hosts to reduce the attack surface.
  • Enable detailed NFS and kernel logs, and monitor for unexpected crashes or NULL‑dereference messages.

Generated by OpenCVE AI on September 20, 2026 at 03:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: NFSv4/pnfs: key the data server cache on the NFS version nfs4_pnfs_ds_add() keys the per-net data server cache on the multipath address set alone, and struct nfs4_pnfs_ds records no version. That suffices for the files layout driver, which always connects with version 4, but flexfiles takes its version tuple from GETDEVICEINFO per device, and one address can legitimately serve both NFSv3 and NFSv4. Two deviceids on one address with different ds_versions[0].version therefore share a single nfs4_pnfs_ds, and whichever mirror connects first pins ds_clp to its own version. The other one is handed that client anyway, so it selects rpc_call_ops for a version the connection does not speak, and the mismatched sequence-slot handling dereferences NULL. Add the version to the cache key so the two cannot alias, giving each version its own nfs4_pnfs_ds and connection while both mirrors stay usable. Only the major version is compared, since that is what selects rpc_call_ops and rpc_ops; v4.0 and v4.1 keep sharing a client. The files layout driver passes the 4 it already hardcodes at connect time.
Title NFSv4/pnfs: key the data server cache on the NFS version
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:53:00.756Z

Reserved: 2026-09-11T19:38:34.786Z

Link: CVE-2026-90102

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:01.910

Modified: 2026-09-18T18:17:41.843

Link: CVE-2026-90102

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:00:09Z

Weaknesses