{"id":"CVE-2026-90104","published":"2026-09-17T17:17:02.217","lastModified":"2026-09-18T18:17:42.190","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nNFSv4.1: zero referring call lists before decoding\n\ndecode_cb_sequence_args() allocates csa_rclists with kmalloc_objs(), so\neach referring_call_list starts uninitialized. decode_rc_list() assigns\nrcl_refcalls only when rcl_nrefcalls is nonzero. A valid list with zero\nreferring calls therefore leaves the pointer uninitialized, and\nnfs4_callback_sequence() later passes stale slab contents to kfree().\n\nAllocate csa_rclists with kzalloc_objs() so every rcl_refcalls member is\nNULL from the beginning, including valid empty referring call lists.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/8fa4804fe62ca4155a2d8fc2789d630376cbf2fc","tags":[]},{"url":"https://git.kernel.org/stable/c/f31f3c042e024aef437cda42f0424ae8d4594b6c","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This flaw in the Linux kernel's NFSv4.1 implementation allows an attacker to cause a kernel memory corruption by passing a zero-length referring call list, leading to potential denial of service or exploitation of vulnerabilities in the kernel.","exploitability":"Exploitation is moderately difficult as it requires crafting a specific input to trigger the vulnerability, and the attacker must have network access to the affected system.","blast_radius":"If exploited, the impact could be severe, potentially leading to a denial of service or further kernel-level attacks, depending on the system's configuration and the presence of other vulnerabilities.","remediation":"Upgrade to the specific version 5.10.100 or later, as published in the advisory.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["dos","kernel","network"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T09:02:55.684Z"}}