Description
In the Linux kernel, the following vulnerability has been resolved:

NFSv4.1: zero referring call lists before decoding

decode_cb_sequence_args() allocates csa_rclists with kmalloc_objs(), so
each referring_call_list starts uninitialized. decode_rc_list() assigns
rcl_refcalls only when rcl_nrefcalls is nonzero. A valid list with zero
referring calls therefore leaves the pointer uninitialized, and
nfs4_callback_sequence() later passes stale slab contents to kfree().

Allocate csa_rclists with kzalloc_objs() so every rcl_refcalls member is
NULL from the beginning, including valid empty referring call lists.
Published: 2026-09-17
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service, potential arbitrary code execution in kernel
Action: Immediate Patch
AI Analysis

Impact

In the Linux kernel, the NFSv4.1 decoder creates callback reference lists that remain uninitialized when no references are present, later freeing these stale pointers with kfree. The resulting memory corruption can crash the kernel and, on the rare occasion where freed memory is reused, allow execution of arbitrary code in kernel space.

Affected Systems

All Linux kernels that include the NFSv4.1 implementation before the commit that replaces kmalloc_objs with kzalloc_objs, typically mainstream distributions before the referenced patch is applied.

Risk and Exploitability

The EPSS is below 1%, indicating a very low chance of current exploitation, and the vulnerability is not listed in CISA KEV. Nonetheless the CVSS score of 9.8 signals a critical risk. The likely path involves a malicious NFS client sending a crafted request with an empty referring‑call list to a server running the affected kernel, inducing the stale free and subsequent crash or code execution.

Generated by OpenCVE AI on September 20, 2026 at 05:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version containing the commit that replaces kmalloc_objs with kzalloc_objs for csa_rclists, ensuring that all referencing call lists are initialized to NULL before use.
  • If an immediate kernel update is not possible, block or drop NFSv4.1 traffic from untrusted clients by configuring firewall rules or disabling the NFSv4.1 protocol on the server.
  • As a temporary repair, apply the patch from the provided kernel commit references that zeros the referring call lists during allocation.

Generated by OpenCVE AI on September 20, 2026 at 05:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-650
CWE-795

Sun, 20 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
CWE-457

Sat, 19 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
CWE-457

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: NFSv4.1: zero referring call lists before decoding decode_cb_sequence_args() allocates csa_rclists with kmalloc_objs(), so each referring_call_list starts uninitialized. decode_rc_list() assigns rcl_refcalls only when rcl_nrefcalls is nonzero. A valid list with zero referring calls therefore leaves the pointer uninitialized, and nfs4_callback_sequence() later passes stale slab contents to kfree(). Allocate csa_rclists with kzalloc_objs() so every rcl_refcalls member is NULL from the beginning, including valid empty referring call lists.
Title NFSv4.1: zero referring call lists before decoding
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:53:03.545Z

Reserved: 2026-09-11T19:38:34.786Z

Link: CVE-2026-90104

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:02.217

Modified: 2026-09-18T18:17:42.190

Link: CVE-2026-90104

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:45:16Z

Weaknesses
  • CWE-650

    Trusting HTTP Permission Methods on the Server Side

  • CWE-795

    Only Filtering Special Elements at a Specified Location