KernelScan.io

CRITICAL Introduced in 2.6.31

nfs CbSequence Corruption

CVE-2026-90104

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.9HIGH

01

In the Linux kernel, the following vulnerability has been resolved: NFSv4.1: zero referring call lists before decoding decode_cb_sequence_args() allocates csa_rclists with kmalloc_objs(), so each referring_call_list starts uninitialized. decode_rc_list() assigns rcl_refcalls only when rcl_nrefcalls is nonzero. A valid list with zero referring calls therefore leaves the pointer uninitialized, and nfs4_callback_sequence() later passes stale slab contents to kfree(). Allocate csa_rclists with kzalloc_objs() so every rcl_refcalls member is NULL from the beginning, including valid empty referring call lists.

02

Engine v0.6.0

Risk summary

Linux systems acting as NFSv4.1 clients are at risk when connected to a malicious or compromised NFS server. The server can send a crafted callback that causes the client kernel to free an uninitialized pointer, leading to kernel heap corruption or a system crash. No special privileges are required on the client beyond having an active NFS mount.

Affectedfs/nfs/callback_xdr.c (NFSv4.1 callback XDR)

Vulnerability analysis

The NFSv4.1 callback handler allocates memory for referring call list data without initializing it, so when a callback message contains a valid referring call list with zero referring calls, an internal pointer retains whatever stale data the allocator left behind. The callback handler later treats that stale value as a valid pointer and frees it, corrupting kernel heap memory or crashing the system. The fix zeroes the allocated memory at allocation time so that any unused pointers are null from the start, making the later cleanup a safe no-op. The vulnerability is reachable over the network from a malicious or compromised NFS server sending a crafted callback to a client that has an active NFSv4.1 mount; no special privileges are required on the client side beyond having mounted the share.

03

BranchIntroducedFixed inPatch commit
mainline2.6.317.3-rc18fa4804fe62c
7.22.6.317.2.6f31f3c042e02