PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-90103 Linux CVE debrief

A vulnerability in the Linux kernel's NFSv4.2 implementation can lead to a denial of service due to a buffer exhaustion issue. The vulnerability is caused by an incorrect budget for the layoutupdate4 body, which can exceed the reserved buffer size. This can lead to a permanent lock hold and potential system crash. The affected product is the Linux kernel, and the vulnerability class is related to buffer exhaustion. The likely operational impact is a denial of service, and the source-confidence limits are based on the official CVE record and NIST NVD detail page.

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-17
Original CVE updated
2026-09-18
Advisory published
2026-09-17
Advisory updated
2026-09-18

Who should care

Linux kernel developers and administrators who use NFSv4.2 in their systems should be aware of this vulnerability and take necessary actions to update their systems. The affected operator is the Linux kernel developer, and the platform is the Linux system. The vulnerability-management impact is related to buffer exhaustion, and the security-team impact is related to denial of service.

Why it matters

This vulnerability can lead to a denial of service and potential system crash due to a buffer exhaustion issue in the Linux kernel's NFSv4.2 implementation. Linux kernel developers and administrators who use NFSv4.2 in their systems should be aware of this vulnerability and take necessary actions to update their systems.

  • Denial of service due to buffer exhaustion
  • Potential system crash due to permanent lock hold

Technical summary

The Linux kernel's NFSv4.2 implementation has a vulnerability that can lead to a denial of service due to a buffer exhaustion issue. The vulnerability is caused by an incorrect budget for the layoutupdate4 body, which can exceed the reserved buffer size. This can lead to a permanent lock hold and potential system crash. The affected product is the Linux kernel, and the vulnerability class is related to buffer exhaustion. The technical framing is based on the official CVE record and NIST NVD detail page, and defenders should review and apply the Linux kernel patch to update the NFSv4.2 implementation.

Defensive priority

High

Recommended defensive actions

  • Review and apply the Linux kernel patch to update the NFSv4.2 implementation
  • Monitor system logs for potential denial of service issues
  • Verify system configurations to ensure that NFSv4.2 is not exposed to untrusted networks
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability is caused by an incorrect budget for the layoutupdate4 body in the NFSv4.2 implementation. The Linux kernel's NFSv4.2 implementation has been updated to resolve this issue. The evidence is based on the official CVE record and NIST NVD detail page, and defenders should verify the affected scope and take necessary actions to update their systems.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-90103 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-90103

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-90103 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-90103

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/3815b894b922e9b4f40b8b6f6d67bf80d44141c9

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/397aa7000bbf6b6a0d32e66a544e978fb478c8e4

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/5aca000630c0fd0da102ae1abf9245dd74f2ce36

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/842ac26615424577f24f0486b9d3bf97f28fad9c

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/a973622da0c62c34043ddbbf382cd761b03e5136

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/c75ef2137e749f2673f0617cfdaae53b2bb7195a

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/cb11590c7ddc6883a1b1d70b1f98b2779fe626f2

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/e82d7d999fe9f893f84bf332fd39cb5d9de7128f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.