CVE-2026-53394 Details
Description
In the Linux kernel, the following vulnerability has been resolved: nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race When find_or_alloc_open_stateowner() encounters an unconfirmed owner, it calls release_openowner() and sets oo = NULL. Control then falls through past the `if (oo)` guard -- which would have freed any pre-allocated `new` -- and unconditionally executes `new = alloc_stateowner(...)`. If `new` was already allocated on a prior iteration, the pointer is silently overwritten and the previous allocation (slab object + owner name buffer) is leaked. This requires a race: two NFSv4.0 OPEN threads with the same owner string, where a concurrent thread inserts a new unconfirmed owner into the hash between retry iterations. The window is narrow but repeatable under adversarial conditions. Fix by adding `goto retry` after `oo = NULL` so the already-allocated `new` is reused on the next iteration rather than overwritten.
A vulnerability in the Linux kernel's NFSv4.0 implementation can lead to a memory leak of pre-allocated open owner objects. This occurs when the function find_or_alloc_open_stateowner() encounters an unconfirmed owner, releases it, and sets the owner variable to NULL. The function then allocates a new owner without first checking if the previous allocation was freed, causing the old allocation to be lost. This issue arises from a race condition where two NFSv4.0 OPEN threads with the same owner string are active, allowing a concurrent thread to insert a new unconfirmed owner into the hash, creating a repeatable leak under specific conditions.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been addressed. Instructions for downloading the patched version are available on the Linux kernel official website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/017a6150106b054cc84d1b0582d97bd3a74d4281 | kernel.org | Patch |
| https://git.kernel.org/stable/c/57aee7a35bb12753057c5b65d72d1f46c0e95b07 | kernel.org | Patch |
| https://git.kernel.org/stable/c/a10bf67fe06469a71a401f72f328237345d553c0 | kernel.org | Patch |
| https://git.kernel.org/stable/c/c9aefb2b5f11337c9202c5bd0c45d71198449718 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-401 | Missing Release of Memory after Effective Lifetime | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 6.10, < 6.12.95 >= 6.13, < 6.18.38 >= 6.19, < 7.1.3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 17, 2026 | CVE Modified | kernel.org |
| Jul 29, 2026 | Initial Analysis | [email protected] |
| Jul 20, 2026 | CVE Modified | kernel.org |
| Jul 19, 2026 | New CVE Received | kernel.org |