Improper Initialization in Linux kernel - CVE-2026-53398
Published: July 21, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper initialization in nfsd4_decode_secinfo_no_name() when processing a truncated XDR stream for the SECINFO_NO_NAME operation. A remote attacker can send a specially crafted request to cause a denial of service.
The issue occurs because stale union contents from a previous operation can leave sin_exp non-NULL, leading the error cleanup path to call exp_put() on an invalid value.
Affected software
Ubuntu
linux-aws (Ubuntu package)
linux-ibm-5.15 (Ubuntu package)
linux-aws-5.15 (Ubuntu package)
linux (Ubuntu package)
linux-azure (Ubuntu package)
linux-oracle-7.0 (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-oem-7.0 (Ubuntu package)
linux-azure-7.0 (Ubuntu package)
How to mitigate CVE-2026-53398
linux-aws (Ubuntu package) - addressed in versions 5.15.0.194.159, 5.15.0-194.204, 5.15.0-194.204~20.04.1, 5.15.0.1079.82, 5.15.0-1079.83, 5.15.0.1099.98, 5.15.0-1099.107, 5.15.0.1108.104, 5.15.0-1108.110, 5.15.0.1108.112, 5.15.0-1108.113, 5.15.0.1110.107, 5.15.0-1110.114, 5.15.0.1111.110, 5.15.0-1111.117, 5.15.0.1112.111, 5.15.0-1112.118, 5.15.0.1113.109, 5.15.0-1113.119, 5.15.0.1115.119, 5.15.0-1115.124, 5.15.0.1116.106, 5.15.0.1116.112, 5.15.0.1116.119, 5.15.0-1116.123, 5.15.0-1116.123+fips1, 5.15.0-1116.126+fips1, 5.15.0.1117.114, 5.15.0-1117.127, 5.15.0-1121.130, 5.15.0.1122.106, 5.15.0.1122.120, 5.15.0-1122.131, 5.15.0-1122.131+fips1
linux-ibm-5.15 (Ubuntu package) - update to 5.15.0-1110.114~20.04.1
linux-aws-5.15 (Ubuntu package) - addressed in versions 5.15.0-1111.117~20.04.1, 5.15.0-1116.123~20.04.1, 5.15.0-1121.130~20.04.1, 5.15.0-1122.131~20.04.1
linux (Ubuntu package) - addressed in versions 7.0.0-31.31, 7.0.0-31.31.1, 7.0.0-31.31~24.04.1, 7.0.0-1006.7, 7.0.0-1011.11~24.04.1, 7.0.0-1012.12, 7.0.0-1012.12~24.04.1
linux-azure (Ubuntu package) - addressed in versions 7.0.0-1011.11, 7.0.0-1014.14
linux-oracle-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1013.13
linux-azure-7.0 (Ubuntu package) - update to 7.0.0-1014.14~24.04.1
External References
- https://git.kernel.org/stable/c/161d1aaeb04d620d3692639700512bb5038c1e10
- https://git.kernel.org/stable/c/1e04be34cafae119e82bcaccd6d28a20f72a3647
- https://git.kernel.org/stable/c/46eb17d45be69d28c7a23ea03283b207426a8232
- https://git.kernel.org/stable/c/49de5d31dd8fdebf78bdeaf196b0ca5cd5c75439
- https://git.kernel.org/stable/c/5ec37edcb534f3fc92304be236d37f08e6545585
- https://git.kernel.org/stable/c/8836405abdc53ca3dd5fc68b2cf6f8f012fad011
- https://git.kernel.org/stable/c/9e18e83b8846a5c3fe13fc8a464b4865d33996c6
- https://git.kernel.org/stable/c/c8a24effd96d4779e2ad779654682304491c55a5
Related Security Bulletins
- Improper Initialization in Linux kernel nfsd
- Ubuntu update for linux-oem-7.0
- Ubuntu update for linux
- Ubuntu update for linux-gcp-7.0
- Ubuntu update for linux-aws-5.15
- Ubuntu update for linux-oracle-7.0
- Ubuntu update for linux-ibm-5.15
- Ubuntu update for linux-aws
- Ubuntu update for linux-azure
- Ubuntu update for linux-azure-7.0