Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.2%top 94%

In the Linux kernel, the following vulnerability has been resolved: NFSv4/flexfiles: reject zero filehandle version count ff_layout_alloc_lseg()… (CVE-2026-53392)

0
Medium
Published: 07/19/2026 (07/19/2026, 12:30:22 UTC)
Source: GCVE Database

Description

A vulnerability in the Linux kernel's NFSv4 flexfiles implementation allowed a zero filehandle version count to be accepted, leading to improper memory allocation and potential kernel panic. The issue occurs because the function ff_layout_alloc_lseg() did not reject a zero count before allocation, resulting in a null-pointer dereference and system crash under certain malformed inputs. The patched kernel now rejects zero counts, preventing this fault and allowing normal operation with valid inputs.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/19/2026, 20:24:55 UTC

Technical Analysis

The Linux kernel's NFSv4 flexfiles component had a vulnerability where ff_layout_alloc_lseg() accepted a zero filehandle version count, which led to the use of ZERO_SIZE_PTR in dss_info->fh_versions. This caused later code to assume at least one filehandle version existed, resulting in a null-pointer dereference and kernel panic when processing malformed flexfiles layouts. The patch adds validation to reject fh_count == 0 before allocation, aligning with existing checks in the flexfiles GETDEVICEINFO parser. Testing with QEMU/KASAN confirmed the issue caused fatal exceptions, which are prevented by the fix.

Potential Impact

The vulnerability can cause a kernel panic due to null-pointer dereference when processing malformed NFSv4 flexfiles layouts with a zero filehandle version count. This leads to denial of service by crashing the kernel. There is no indication of code execution or data corruption beyond the crash. No known exploits are reported in the wild.

Mitigation Recommendations

A patch has been applied to the Linux kernel to reject zero filehandle version counts before allocation, preventing the null-pointer dereference and kernel panic. Users should update to the fixed kernel version once available. Since this is a kernel-level issue, applying the official kernel update is the recommended remediation. Patch status is not explicitly stated in the provided data; check the vendor advisory for the exact fixed versions and update instructions.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-3gfh-mq5v-c264
Osv Schema Version
1.4.0
Aliases
["CVE-2026-53392"]
Ecosystems
[]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a5d27ad2a4a8d59891325c9

Added to database: 07/19/2026, 19:38:21 UTC

Last enriched: 07/19/2026, 20:24:55 UTC

Last updated: 07/20/2026, 17:26:47 UTC

Views: 16

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses