Description
In the Linux kernel, the following vulnerability has been resolved:

NFSv4.2: fix LAYOUTSTATS send buffer exhaustion

encode_layoutstats_maxsz budgets XDR_QUADLEN(PNFS_LAYOUTSTATS_MAXSIZE),
i.e. 256 bytes, for the layoutupdate4 body written by the layout driver.
The flexfiles record can exceed that.

ff_layout_encode_ff_layoutupdate() emits, per data server, a netaddr4,
an nfs_fh4, two ff_io_latency4, an nfstime4 and a bool. A data server
whose filehandle is NFS_MAXFHSIZE bytes long already accounts for 132 of
those bytes, and the two ff_io_latency4 at 64 bytes each, the nfstime4
and the bool add a further 144, so the body passes 256 bytes before the
netaddr4 is encoded at all. encode_layoutstats() additionally writes
the deviceid4 and the layoutupdate4 lou_type word, neither of which the
macro accounts for.

The filehandle and the address are both chosen by the server, through
LAYOUTGET and GETDEVICEINFO, so it can drive the encoder past the
end of the send buffer. xdr_reserve_space() returns NULL once that
happens, and the two ff_layout_encode_io_latency() calls run with
dss_info->mirror->lock held, so a NULL return there leaves the lock
permanently held.

Raise PNFS_LAYOUTSTATS_MAXSIZE to 384 so that the record fits inside the
reservation.
Published: 2026-09-17
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via NFSv4.2 LAYOUTSTATS send buffer exhaustion
Action: Patch
AI Analysis

Impact

The vulnerability is an internal error in the Linux kernel’s NFSv4.2 implementation where the layout statistics encoder reserves only 256 bytes for the payload but may generate larger messages. When a server includes a filehandle close to the maximum size and adds additional latency information, the encoded payload exceeds the reserved buffer. This causes the XDR allocator to return NULL while a lock is held, leaving the synchronization primitive permanently blocked. The result is that subsequent NFS operations that require the lock cannot complete, effectively denying service to all clients that rely on the affected NFS server.

Affected Systems

The flaw appears in all Linux kernel versions prior to the patch that raises PNFS_LAYOUTSTATS_MAXSIZE to 384 bytes. The affected code resides in the mainline kernel source; thus any distribution shipping a kernel with the 256‑byte limit is vulnerable. The threat applies only to systems exposing NFSv4.2 and that allow the layout statistics feature; it does not affect earlier protocol versions or non‑NFS services.

Risk and Exploitability

The CVSS score is 7.5, indicating a high impact vulnerability. The EPSS score of < 1% suggests the likelihood of exploitation is currently low, and the feature is not listed in the CISA KEV catalog. An attacker would need to control a malicious NFS client that requests layout statistics, causing the server’s encoder to exceed the reserved buffer and hold a lock indefinitely. Once the lock is held, the server’s NFS daemon stalls, requiring a reboot or manual intervention to restore service.

Generated by OpenCVE AI on September 20, 2026 at 03:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version where PNFS_LAYOUTSTATS_MAXSIZE is increased to 384 bytes.
  • Disable or limit the LAYOUTSTATS feature by configuring the NFS server to use an older protocol version such as NFSv4.1 or by disabling the feature if an option is available, to avoid the vulnerability when a patch is not immediately possible.
  • Restrict NFS exports to trusted hosts and monitor the NFS daemon for lock contention or stalls; restart the NFS service or reboot the system if a lock freeze is detected.

Generated by OpenCVE AI on September 20, 2026 at 03:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-76

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: NFSv4.2: fix LAYOUTSTATS send buffer exhaustion encode_layoutstats_maxsz budgets XDR_QUADLEN(PNFS_LAYOUTSTATS_MAXSIZE), i.e. 256 bytes, for the layoutupdate4 body written by the layout driver. The flexfiles record can exceed that. ff_layout_encode_ff_layoutupdate() emits, per data server, a netaddr4, an nfs_fh4, two ff_io_latency4, an nfstime4 and a bool. A data server whose filehandle is NFS_MAXFHSIZE bytes long already accounts for 132 of those bytes, and the two ff_io_latency4 at 64 bytes each, the nfstime4 and the bool add a further 144, so the body passes 256 bytes before the netaddr4 is encoded at all. encode_layoutstats() additionally writes the deviceid4 and the layoutupdate4 lou_type word, neither of which the macro accounts for. The filehandle and the address are both chosen by the server, through LAYOUTGET and GETDEVICEINFO, so it can drive the encoder past the end of the send buffer. xdr_reserve_space() returns NULL once that happens, and the two ff_layout_encode_io_latency() calls run with dss_info->mirror->lock held, so a NULL return there leaves the lock permanently held. Raise PNFS_LAYOUTSTATS_MAXSIZE to 384 so that the record fits inside the reservation.
Title NFSv4.2: fix LAYOUTSTATS send buffer exhaustion
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:53:02.167Z

Reserved: 2026-09-11T19:38:34.786Z

Link: CVE-2026-90103

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:02.063

Modified: 2026-09-18T18:17:42.017

Link: CVE-2026-90103

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:15:08Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-76

    Improper Neutralization of Equivalent Special Elements