Incorrect Calculation of Buffer Size in Linux kernel - CVE-2026-90103
Published: September 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to incorrect buffer size calculation in the NFSv4.2 flexfiles layoutstats encoder when encoding layout statistics for a flexfiles layout. A remote attacker can provide crafted server-controlled filehandle and network-address data to exhaust the send buffer and leave a lock permanently held to cause a denial of service.
Affected software
How to mitigate CVE-2026-90103
External References
- https://git.kernel.org/stable/c/3815b894b922e9b4f40b8b6f6d67bf80d44141c9
- https://git.kernel.org/stable/c/397aa7000bbf6b6a0d32e66a544e978fb478c8e4
- https://git.kernel.org/stable/c/5aca000630c0fd0da102ae1abf9245dd74f2ce36
- https://git.kernel.org/stable/c/842ac26615424577f24f0486b9d3bf97f28fad9c
- https://git.kernel.org/stable/c/a973622da0c62c34043ddbbf382cd761b03e5136
- https://git.kernel.org/stable/c/c75ef2137e749f2673f0617cfdaae53b2bb7195a
- https://git.kernel.org/stable/c/cb11590c7ddc6883a1b1d70b1f98b2779fe626f2
- https://git.kernel.org/stable/c/e82d7d999fe9f893f84bf332fd39cb5d9de7128f