GPU VulnDB

Database/Control plane, storage & DevOps

Linux NFS server (nfsd, SECINFO_NO_NAME decode): A truncated SECINFO_NO_NAME operation leaves sin_exp uninitialized and

CVE-2026-53398Control plane, storage & DevOpscurated

Impact

A truncated SECINFO_NO_NAME operation leaves sin_exp uninitialized and the error path then acts on it, corrupting kernel memory on the file server. A malformed compound from an unauthenticated client is enough.

Who can reach it

Any host that can send NFSv4 traffic to the server's RPC port.

What to do

Update the storage server kernel to one with the decode cleanup fix and reboot.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.