VulnWatch VulnWatch
← Back to dashboard
Unknown nvd · CVE-2026-53394

CVE-2026-53394: In the Linux kernel, the following vulnerability has been resolved: nfsd: avoid leaking pre-allocated openowner on unco

Published Jul 19, 2026

In the Linux kernel, the following vulnerability has been resolved:

nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race

When find_or_alloc_open_stateowner() encounters an unconfirmed owner, it calls release_openowner() and sets oo = NULL. Control then falls through past the if (oo) guard -- which would have freed any pre-allocated new -- and unconditionally executes new = alloc_stateowner(...). If new was already allocated on a prior iteration, the pointer is silently overwritten and the previous allocation (slab object + owner name buffer) is leaked.

This requires a race: two NFSv4.0 OPEN threads with the same owner string, where a concurrent thread inserts a new unconfirmed owner into the hash between retry iterations. The window is narrow but repeatable under adversarial conditions.

Fix by adding goto retry after oo = NULL so the already-allocated new is reused on the next iteration rather than overwritten.

Affected AI Products

adversarial
Get the weekly digest. Every Monday: top AI security stories of the week. Free.