PT-2026-94451 · Linux · Linux Kernel
CVE-2026-90103
·
Published
2026-09-17
·
Updated
2026-09-24
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the NFSv4.2 implementation where the
encode layoutstats maxsz budget is insufficient for the layoutupdate4 body written by the layout driver. Specifically, the ff layout encode ff layoutupdate() function can emit data that exceeds the 256-byte limit, especially when handling data servers with large filehandles. Because the server controls the filehandle and address via LAYOUTGET and GETDEVICEINFO, it can force the encoder beyond the send buffer limit. When xdr reserve space() returns NULL due to this exhaustion, the ff layout encode io latency() calls may leave the dss info->mirror->lock permanently held, leading to a deadlock.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel