SB20260919106 - Incorrect Calculation of Buffer Size in Linux kernel NFSv4.2 flexfiles layoutstats encoder
Published: September 19, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Incorrect Calculation of Buffer Size (CVE-ID: CVE-2026-90103)
CWE-ID: CWE-131 - Incorrect Calculation of Buffer Size
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to incorrect buffer size calculation in the NFSv4.2 flexfiles layoutstats encoder when encoding layout statistics for a flexfiles layout. A remote attacker can provide crafted server-controlled filehandle and network-address data to exhaust the send buffer and leave a lock permanently held to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/3815b894b922e9b4f40b8b6f6d67bf80d44141c9
- https://git.kernel.org/stable/c/397aa7000bbf6b6a0d32e66a544e978fb478c8e4
- https://git.kernel.org/stable/c/5aca000630c0fd0da102ae1abf9245dd74f2ce36
- https://git.kernel.org/stable/c/842ac26615424577f24f0486b9d3bf97f28fad9c
- https://git.kernel.org/stable/c/a973622da0c62c34043ddbbf382cd761b03e5136
- https://git.kernel.org/stable/c/c75ef2137e749f2673f0617cfdaae53b2bb7195a
- https://git.kernel.org/stable/c/cb11590c7ddc6883a1b1d70b1f98b2779fe626f2
- https://git.kernel.org/stable/c/e82d7d999fe9f893f84bf332fd39cb5d9de7128f