Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-53398

Gravedad CVSS v3.1:
CRÍTICA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
19/07/2026
Última modificación:
29/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> NFSD: Fix SECINFO_NO_NAME decode error cleanup<br /> <br /> nfsd4_decode_secinfo_no_name() currently initializes sin_exp after<br /> decoding sin_style. If the XDR stream is truncated, the decoder returns<br /> nfserr_bad_xdr before sin_exp is initialized.<br /> <br /> Since commit 3fdc54646234 ("NFSD: Reduce amount of struct<br /> nfsd4_compoundargs that needs clearing"), the inline iops array is not<br /> cleared between RPC calls. A failed SECINFO_NO_NAME decode can therefore<br /> leave sin_exp holding stale union contents from a previous operation.<br /> <br /> The error response path still invokes nfsd4_secinfo_no_name_release(),<br /> which calls exp_put() on a non-NULL sin_exp.<br /> <br /> Initialize sin_exp before the first failable decode step, matching<br /> nfsd4_decode_secinfo().

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.10.220 (incluyendo) 5.10.260 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.15.154 (incluyendo) 5.15.211 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.1 (incluyendo) 6.1.177 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (incluyendo) 6.6.144 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (incluyendo) 6.12.95 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (incluyendo) 6.18.38 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (incluyendo) 7.1.3 (excluyendo)