In the Linux kernel, the following vulnerability has been resolved: NFSv4.2: fix LAYOUTSTATS send buffer exhaustion encode_layoutstats_maxsz budgets… (CVE-2026-90103)
A vulnerability in the Linux kernel's NFSv4.2 implementation related to LAYOUTSTATS send buffer exhaustion has been resolved. The issue arises because the encoding of layout statistics can exceed the reserved buffer size, potentially causing a buffer exhaustion. This can lead to a permanent lock being held due to a NULL pointer return during encoding. The fix involves increasing the maximum buffer size to accommodate the full record.
AI Analysis
Technical Summary
The vulnerability in the Linux kernel NFSv4.2 subsystem involves the encoding of layout statistics (LAYOUTSTATS) for pNFS layout updates. The macro encode_layoutstats_maxsz originally budgets 256 bytes for the layoutupdate4 body, but the actual data, including filehandle and address information controlled by the server, can exceed this size. When the send buffer is exhausted, xdr_reserve_space() returns NULL, causing functions that hold locks to fail to release them, resulting in a permanent lock. The patch raises PNFS_LAYOUTSTATS_MAXSIZE to 384 bytes to ensure the record fits within the buffer reservation, preventing buffer exhaustion and lock retention.
Potential Impact
The vulnerability can cause a denial of service condition by exhausting the send buffer during layout statistics encoding, which leads to a NULL pointer return and a lock being permanently held. This results in an availability impact (denial of service) without compromising confidentiality or integrity.
Mitigation Recommendations
A fix is available that increases the buffer size to prevent exhaustion and the associated lock retention. Users should apply the official Linux kernel patch that raises PNFS_LAYOUTSTATS_MAXSIZE to 384 bytes. No additional mitigation is indicated.
In the Linux kernel, the following vulnerability has been resolved: NFSv4.2: fix LAYOUTSTATS send buffer exhaustion encode_layoutstats_maxsz budgets… (CVE-2026-90103)
Description
A vulnerability in the Linux kernel's NFSv4.2 implementation related to LAYOUTSTATS send buffer exhaustion has been resolved. The issue arises because the encoding of layout statistics can exceed the reserved buffer size, potentially causing a buffer exhaustion. This can lead to a permanent lock being held due to a NULL pointer return during encoding. The fix involves increasing the maximum buffer size to accommodate the full record.
CVSS v3.1
Score 7.5high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in the Linux kernel NFSv4.2 subsystem involves the encoding of layout statistics (LAYOUTSTATS) for pNFS layout updates. The macro encode_layoutstats_maxsz originally budgets 256 bytes for the layoutupdate4 body, but the actual data, including filehandle and address information controlled by the server, can exceed this size. When the send buffer is exhausted, xdr_reserve_space() returns NULL, causing functions that hold locks to fail to release them, resulting in a permanent lock. The patch raises PNFS_LAYOUTSTATS_MAXSIZE to 384 bytes to ensure the record fits within the buffer reservation, preventing buffer exhaustion and lock retention.
Potential Impact
The vulnerability can cause a denial of service condition by exhausting the send buffer during layout statistics encoding, which leads to a NULL pointer return and a lock being permanently held. This results in an availability impact (denial of service) without compromising confidentiality or integrity.
Mitigation Recommendations
A fix is available that increases the buffer size to prevent exhaustion and the associated lock retention. Users should apply the official Linux kernel patch that raises PNFS_LAYOUTSTATS_MAXSIZE to 384 bytes. No additional mitigation is indicated.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-qgw9-h34w-h93j
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-90103"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6aade52855bf5e2cf5edc1ca
Added to database: 09/19/2026, 01:28:08 UTC
Last enriched: 09/19/2026, 01:54:37 UTC
Last updated: 09/19/2026, 03:32:53 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.