---
cve: "CVE-2026-53398"
severity: "CRITICAL"
cvss: 9.8
epss: "51%"
vendor: "Linux"
kev: false
exploited: false
published: "2026-07-19 12:16:50"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-11T00:04:02+02:00"
---

# CVE-2026-53398

> 9.8 CRITICAL

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

NFSD: Fix SECINFO_NO_NAME decode error cleanup

nfsd4_decode_secinfo_no_name() currently initializes sin_exp after
decoding sin_style. If the XDR stream is truncated, the decoder returns
nfserr_bad_xdr before sin_exp is initialized.

Since commit 3fdc54646234 ("NFSD: Reduce amount of struct
nfsd4_compoundargs that needs clearing"), the inline iops array is not
cleared between RPC calls. A failed SECINFO_NO_NAME decode can therefore
leave sin_exp holding stale union contents from a previous operation.

The error response path still invokes nfsd4_secinfo_no_name_release(),
which calls exp_put() on a non-NULL sin_exp.

Initialize sin_exp before the first failable decode step, matching
nfsd4_decode_secinfo().

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Patch verfügbar (OSV)

- Kernel ≥ 5.10.260
- Kernel ≥ 5.15.211
- Kernel ≥ 6.1.177
- Kernel ≥ 6.6.144
- Kernel ≥ 6.12.95
- Kernel ≥ 6.18.38
- Kernel ≥ 7.1.3

## Referenzen

- <https://git.kernel.org/stable/c/8836405abdc53ca3dd5fc68b2cf6f8f012fad011>
- <https://git.kernel.org/stable/c/49de5d31dd8fdebf78bdeaf196b0ca5cd5c75439>
- <https://git.kernel.org/stable/c/5ec37edcb534f3fc92304be236d37f08e6545585>
- <https://git.kernel.org/stable/c/1e04be34cafae119e82bcaccd6d28a20f72a3647>
- <https://git.kernel.org/stable/c/161d1aaeb04d620d3692639700512bb5038c1e10>
- <https://git.kernel.org/stable/c/c8a24effd96d4779e2ad779654682304491c55a5>
- <https://git.kernel.org/stable/c/46eb17d45be69d28c7a23ea03283b207426a8232>
- <https://git.kernel.org/stable/c/9e18e83b8846a5c3fe13fc8a464b4865d33996c6>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-53398) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
