{"id":"CVE-2026-53398","summary":"NFSD: Fix SECINFO_NO_NAME decode error cleanup","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: Fix SECINFO_NO_NAME decode error cleanup\n\nnfsd4_decode_secinfo_no_name() currently initializes sin_exp after\ndecoding sin_style. If the XDR stream is truncated, the decoder returns\nnfserr_bad_xdr before sin_exp is initialized.\n\nSince commit 3fdc54646234 (\"NFSD: Reduce amount of struct\nnfsd4_compoundargs that needs clearing\"), the inline iops array is not\ncleared between RPC calls. A failed SECINFO_NO_NAME decode can therefore\nleave sin_exp holding stale union contents from a previous operation.\n\nThe error response path still invokes nfsd4_secinfo_no_name_release(),\nwhich calls exp_put() on a non-NULL sin_exp.\n\nInitialize sin_exp before the first failable decode step, matching\nnfsd4_decode_secinfo().","modified":"2026-07-22T05:29:48.578214558Z","published":"2026-07-19T12:01:59.507Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53398.json","cna_assigner":"Linux"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/161d1aaeb04d620d3692639700512bb5038c1e10"},{"type":"WEB","url":"https://git.kernel.org/stable/c/1e04be34cafae119e82bcaccd6d28a20f72a3647"},{"type":"WEB","url":"https://git.kernel.org/stable/c/46eb17d45be69d28c7a23ea03283b207426a8232"},{"type":"WEB","url":"https://git.kernel.org/stable/c/49de5d31dd8fdebf78bdeaf196b0ca5cd5c75439"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5ec37edcb534f3fc92304be236d37f08e6545585"},{"type":"WEB","url":"https://git.kernel.org/stable/c/8836405abdc53ca3dd5fc68b2cf6f8f012fad011"},{"type":"WEB","url":"https://git.kernel.org/stable/c/9e18e83b8846a5c3fe13fc8a464b4865d33996c6"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c8a24effd96d4779e2ad779654682304491c55a5"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53398.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53398"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"5e76b25d7cc82c148d391c0c43b884e6427cb302"},{"fixed":"8836405abdc53ca3dd5fc68b2cf6f8f012fad011"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"07b68ff5c71cf4ed5443016d8eb116863c0a4d88"},{"fixed":"49de5d31dd8fdebf78bdeaf196b0ca5cd5c75439"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"3fdc546462348b8a497c72bc894e0cde9f10fc40"},{"fixed":"5ec37edcb534f3fc92304be236d37f08e6545585"},{"fixed":"1e04be34cafae119e82bcaccd6d28a20f72a3647"},{"fixed":"161d1aaeb04d620d3692639700512bb5038c1e10"},{"fixed":"c8a24effd96d4779e2ad779654682304491c55a5"},{"fixed":"46eb17d45be69d28c7a23ea03283b207426a8232"},{"fixed":"9e18e83b8846a5c3fe13fc8a464b4865d33996c6"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"5.10.220"},{"fixed":"5.10.260"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"5.15.154"},{"fixed":"5.15.211"}]}],"versions":["v5.10.259","v5.10.258","v5.10.257","v5.10.256","v5.10.255","v5.10.254","v5.10.253","v5.10.252","v5.10.251","v5.10.250","v5.10.249","v5.10.248","v5.10.247","v5.10.246","v5.10.245","v5.10.244","v5.10.243","v5.10.242","v5.10.241","v5.10.240","v5.10.239","v5.10.238","v5.10.237","v5.10.236","v5.10.235","v5.10.234","v5.10.233","v5.10.232","v5.10.231","v5.10.230","v5.10.229","v5.10.228","v5.10.227","v5.10.226","v5.10.225","v5.10.224","v5.10.223","v5.10.222","v5.10.221","v5.10.220","v5.15.210","v5.15.209","v5.15.208","v5.15.207","v5.15.206","v5.15.205","v5.15.204","v5.15.203","v5.15.202","v5.15.201","v5.15.200","v5.15.199","v5.15.198","v5.15.197","v5.15.196","v5.15.195","v5.15.194","v5.15.193","v5.15.192","v5.15.191","v5.15.190","v5.15.189","v5.15.188","v5.15.187","v5.15.186","v5.15.185","v5.15.184","v5.15.183","v5.15.182","v5.15.181","v5.15.180","v5.15.179","v5.15.178","v5.15.177","v5.15.176","v5.15.175","v5.15.174","v5.15.173","v5.15.172","v5.15.171","v5.15.170","v5.15.169","v5.15.168","v5.15.167","v5.15.166","v5.15.165","v5.15.164","v5.15.163","v5.15.162","v5.15.161","v5.15.160","v5.15.159","v5.15.158","v5.15.157","v5.15.156","v5.15.155","v5.15.154"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53398.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.10.260"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.211"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.177"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.1.0"},{"fixed":"6.6.144"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.12.95"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.18.38"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"7.1.3"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53398.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}