PT-2026-43850 · Linux+2 · Linux Kernel+2
CVE-2026-45983
·
Published
2025-12-22
·
Updated
2026-08-23
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the nfsd component where certain operations, such as SETATTR, can trigger idmap lookup upcalls during v4 request compound argument decoding. If these upcall responses are delayed beyond the allowed time limit, the
cache check() function marks the request for deferral, causing it to be dropped. This prevents the nfs4svc encode compoundres() function from executing, which leaves the session slot flag NFSD4 SLOT INUSE uncleared. Consequently, subsequent client requests fail with NFSERR JUKEBOX because the slot remains marked as in-use, causing the SEQUENCE operation to fail.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Missing Release of Resource after Effective Lifetime
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Ubuntu