PT-2026-61097 · Linux+2 · Linux Kernel+2

CVE-2026-53392

·

Published

2026-07-19

·

Updated

2026-09-07

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the NFSv4 flexfiles implementation where the ff layout alloc lseg() function fails to properly validate the filehandle-version array count decoded from the flexfiles layout body. When a zero count is provided, it is passed to kzalloc objs(), resulting in a ZERO SIZE PTR being stored in dss info->fh versions. Because subsequent flexfiles paths assume at least one filehandle version is present, this leads to a null-pointer dereference, which can cause a kernel panic.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:61887
ALSA-2026:63013
ALSA-2026:63014
ALSA-2026:63129
AZL-92540
CVE-2026-53392
ECHO-98AB-CF50-B2FD
OESA-2026-3316
OESA-2026-3453
OPENSUSE-SU-2026:11339-1
OPENSUSE-SU-2026:21555-1
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23193-1
SUSE-SU-2026:23194-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1
SUSE-SU-2026:23241-1
SUSE-SU-2026:23244-1
SUSE-SU-2026:3594-1
SUSE-SU-2026:3790-1
SUSE-SU-2026:3810-1
USN-8726-1
USN-8727-1
USN-8728-1

Affected Products

Linux Kernel
Rocky Linux
Ubuntu