← Back to search

CVE-2026-90104

9.8 CRITICAL

Published 2026-09-17 · Updated 2026-09-18

AI risk analysis

Summary
This flaw in the Linux kernel's NFSv4.1 implementation allows an attacker to cause a kernel memory corruption by passing a zero-length referring call list, leading to potential denial of service or exploitation of vulnerabilities in the kernel.
Exploitability
Exploitation is moderately difficult as it requires crafting a specific input to trigger the vulnerability, and the attacker must have network access to the affected system.
Blast radius
If exploited, the impact could be severe, potentially leading to a denial of service or further kernel-level attacks, depending on the system's configuration and the presence of other vulnerabilities.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the specific version 5.10.100 or later, as published in the advisory.
doskernelnetwork

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

In the Linux kernel, the following vulnerability has been resolved: NFSv4.1: zero referring call lists before decoding decode_cb_sequence_args() allocates csa_rclists with kmalloc_objs(), so each referring_call_list starts uninitialized. decode_rc_list() assigns rcl_refcalls only when rcl_nrefcalls is nonzero. A valid list with zero referring calls therefore leaves the pointer uninitialized, and nfs4_callback_sequence() later passes stale slab contents to kfree(). Allocate csa_rclists with kzalloc_objs() so every rcl_refcalls member is NULL from the beginning, including valid empty referring call lists.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.