{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90104","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.786Z","datePublished":"2026-09-17T16:06:14.191Z","dateUpdated":"2026-09-18T17:53:03.545Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:53:03.545Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nNFSv4.1: zero referring call lists before decoding\n\ndecode_cb_sequence_args() allocates csa_rclists with kmalloc_objs(), so\neach referring_call_list starts uninitialized. decode_rc_list() assigns\nrcl_refcalls only when rcl_nrefcalls is nonzero. A valid list with zero\nreferring calls therefore leaves the pointer uninitialized, and\nnfs4_callback_sequence() later passes stale slab contents to kfree().\n\nAllocate csa_rclists with kzalloc_objs() so every rcl_refcalls member is\nNULL from the beginning, including valid empty referring call lists."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - xs_read_stream_call()/rpcrdma_bc_receive_call() deliver a backchannel RPC_CALL on the established NFSv4.1 TCP or RPC/RDMA session into nfs4_callback_compound → process_op → decode_cb_sequence_args(); the attacker-controlled bytes are the CB_SEQUENCE csa_nrclists and rcl_nrefcalls XDR fields sent by the NFS server.\nAC:L - A single well-formed CB_SEQUENCE with csa_nrclists≥1 and decode_rc_list() seeing rcl_nrefcalls==0 skips the rcl_refcalls assignment and still returns 0; nfs4_callback_sequence() then kfree()s that stale pointer. Empty referring_call_list4 is valid RFC 5661 XDR, so no race or victim-only state is required.\nPR:N - nfs_callback_authenticate() accepts RPC_AUTH_UNIX on the NFSv4.1 backchannel, and decode_cb_sequence_args() runs in process_op() before nfs4_find_client_sessionid(); the connected NFS server needs no account or capability on the client to send CB_SEQUENCE.\nUI:N - After nfs4_init_callback() has attached the backchannel (boot-time, autofs, or Kubernetes NFSv4.1 mounts), the server unilaterally sends CB_SEQUENCE; nfs4_callback_sequence() kfree()s rcl_refcalls with no further victim open, mount, or click.\nS:U - kfree of the stale rcl_refcalls pointer corrupts the NFS client's kmalloc heap in the same host kernel; it does not cross a VM, IOMMU, or guest/host boundary.\nC:H - nfs4_callback_sequence() kfree()s uninitialized rcl_refcalls left by kmalloc_objs() of csa_rclists when rcl_nrefcalls was 0. A prior CB_SEQUENCE that allocated then freed rcl_refcalls can leave that pointer in the reused slab object, a heap double-free/UAF read primitive.\nI:H - The same kfree of stale rcl_refcalls is a slab double-free of the referring_call array (size chosen by the attacker's earlier nrefcalls). Reclaim or spraying a replacement object over that free yields an arbitrary kernel write / control-flow hijack primitive.\nA:H - kfree of a non-NULL garbage rcl_refcalls pointer from a successful decode_cb_sequence_args() of an empty referring_call_list causes SLUB to BUG, oops, or panic even when the double-free is not fully exploited."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfs/callback_xdr.c"],"versions":[{"version":"4aece6a19cf7f474f15eb861ba74db4479884ce3","lessThan":"f31f3c042e024aef437cda42f0424ae8d4594b6c","status":"affected","versionType":"git"},{"version":"4aece6a19cf7f474f15eb861ba74db4479884ce3","lessThan":"8fa4804fe62ca4155a2d8fc2789d630376cbf2fc","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfs/callback_xdr.c"],"versions":[{"version":"2.6.31","status":"affected"},{"version":"0","lessThan":"2.6.31","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.31","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.31","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/f31f3c042e024aef437cda42f0424ae8d4594b6c"},{"url":"https://git.kernel.org/stable/c/8fa4804fe62ca4155a2d8fc2789d630376cbf2fc"}],"title":"NFSv4.1: zero referring call lists before decoding","x_generator":{"engine":"bippy-1.2.0"}}}}