Improper control of a resource through its lifetime in Linux kernel - CVE-2026-45983

 

Improper control of a resource through its lifetime in Linux kernel - CVE-2026-45983

Published: May 28, 2026


Vulnerability identifier: #VU132508
CSH Severity: Medium
CVSS v4 BT: 4.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2026-45983
CWE-ID: CWE-664
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper state management in nfs4 compound request handling when processing v4 request compound arguments that trigger idmap lookup upcalls. A remote user can send a crafted NFSv4 request to cause a denial of service.

When idmap lookup upcall responses are delayed beyond the allowed time limit, the request can be dropped before the compound response is encoded, leaving the session slot marked as in use and causing subsequent client requests to fail with NFSERR_JUKEBOX.


Affected software

Linux kernel
Ubuntu
openEuler
bpftool
bpftool-debuginfo
kernel-debuginfo
kernel-debugsource
kernel-devel
kernel-headers
kernel-source
kernel-tools
kernel-tools-debuginfo
kernel-tools-devel
perf
perf-debuginfo
python3-perf
python3-perf-debuginfo
kernel
linux (Ubuntu package)
linux-aws (Ubuntu package)
linux-nvidia-tegra (Ubuntu package)
linux-nvidia-tegra-5.15 (Ubuntu package)
linux-ibm-5.15 (Ubuntu package)
linux-azure (Ubuntu package)
linux-azure-5.15 (Ubuntu package)
linux-azure-fips (Ubuntu package)
linux-azure-fde (Ubuntu package)
linux-hwe-6.8 (Ubuntu package)
linux-aws-6.8 (Ubuntu package)
linux-raspi (Ubuntu package)
linux-azure-fde-6.8 (Ubuntu package)
linux-raspi-realtime (Ubuntu package)

How to mitigate CVE-2026-45983

Install security update from vendor's repository.

bpftool - update to 5.10.0-318.0.0.221
bpftool-debuginfo - update to 5.10.0-318.0.0.221
kernel-debuginfo - update to 5.10.0-318.0.0.221
kernel-debugsource - update to 5.10.0-318.0.0.221
kernel-devel - update to 5.10.0-318.0.0.221
kernel-headers - update to 5.10.0-318.0.0.221
kernel-source - update to 5.10.0-318.0.0.221
kernel-tools - update to 5.10.0-318.0.0.221
kernel-tools-debuginfo - update to 5.10.0-318.0.0.221
kernel-tools-devel - update to 5.10.0-318.0.0.221
perf - update to 5.10.0-318.0.0.221
perf-debuginfo - update to 5.10.0-318.0.0.221
python3-perf - update to 5.10.0-318.0.0.221
python3-perf-debuginfo - update to 5.10.0-318.0.0.221
kernel - update to 5.10.0-318.0.0.221
linux (Ubuntu package) - addressed in versions 5.15.0.184.155, 5.15.0-184.194, 5.15.0-184.194~20.04.1, 5.15.0.186.166, 5.15.0-186.196, 5.15.0-186.196~20.04.1, 5.15.0.1075.78, 5.15.0-1075.79, 5.15.0.1095.94, 5.15.0-1095.103, 5.15.0.1104.100, 5.15.0-1104.109, 5.15.0.1108.107, 5.15.0-1108.114, 5.15.0.1111.115, 5.15.0-1111.120+fips1, 5.15.0.1112.102, 5.15.0.1112.109, 5.15.0-1112.122, 5.15.0-1112.122+fips1, 6.8.0-134.134, 6.8.0-1057.58~22.04.1, 6.8.0-1058.61+fips1, 6.8.0-1058.61~22.04.1, 6.8.0-1060.61, 6.8.0-1060.63+fips1, 6.8.0-1060.63~22.04.1, 6.8.0-1063.69, 6.8.0-1063.69+fips1, 6.8.1-1055.56, 6.8.1-1055.56~22.04.1
linux-aws (Ubuntu package) - addressed in versions 5.15.0.186.109, 5.15.0-186.196+fips1, 5.15.0.1106.103, 5.15.0-1106.110, 5.15.0.1107.107, 5.15.0-1107.108, 5.15.0.1112.108, 5.15.0.1112.115, 5.15.0-1112.119, 5.15.0-1112.119+fips1, 5.15.0-1112.119~20.04.1
linux-nvidia-tegra (Ubuntu package) - addressed in versions 5.15.0-1053.53, 5.15.0.1053.55, 5.15.0.1064.64, 5.15.0-1064.66, 6.8.0-1029.30
linux-nvidia-tegra-5.15 (Ubuntu package) - update to 5.15.0-1064.66~20.04.1
linux-ibm-5.15 (Ubuntu package) - update to 5.15.0-1106.110~20.04.1
linux-azure (Ubuntu package) - addressed in versions 5.15.0.1109.105, 5.15.0-1109.115, 5.15.0.1117.115, 5.15.0-1117.126, 6.8.0-1063.71, 6.8.0-1063.71~22.04.1
linux-azure-5.15 (Ubuntu package) - addressed in versions 5.15.0-1109.115~20.04.1, 5.15.0-1117.126~20.04.1, 5.15.0-1117.126~20.04.2
linux-azure-fips (Ubuntu package) - addressed in versions 5.15.0.1117.102, 5.15.0-1117.126+fips1, 6.8.0-134.134+fips1, 6.8.0-1062.69+fips1
linux-azure-fde (Ubuntu package) - addressed in versions 5.15.0-1117.126, 6.8.0-1062.69
linux-hwe-6.8 (Ubuntu package) - update to 6.8.0-136.136~22.04.1
linux-aws-6.8 (Ubuntu package) - addressed in versions 6.8.0-1045.48, 6.8.0-1057.58~22.04.1, 6.8.0-1058.61.1, 6.8.0-1058.64, 6.8.0-1060.61~22.04.1, 6.8.0-1060.63~22.04.1, 6.8.0-1063.69~22.04.1
linux-raspi (Ubuntu package) - update to 6.8.0-1060.64
linux-azure-fde-6.8 (Ubuntu package) - update to 6.8.0-1062.69~22.04.1
linux-raspi-realtime (Ubuntu package) - update to 6.8.0-2049.50

External References

Related Security Bulletins