In the Linux kernel, the following vulnerability has been resolved:
pNFS: Fix use-after-free in pnfs_update_layout()
When hitting the NFS_LAYOUT_RETURN branch in pnfs_update_layout(),
the code calls pnfs_prepare_to_retry_layoutget(lo). If it succeeds,
pnfs_put_layout_hdr(lo) is called before trace_pnfs_update_layout(),
which still references 'lo'. This results in a use-after-free when the
tracepoint accesses lo's fields.
Fix this by moving the tracepoint call before pnfs_put_layout_hdr(lo).
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-07-19 12:16
Updated : 2026-08-17 05:17
NVD link : CVE-2026-63800
Mitre link : CVE-2026-63800
CVE.ORG link : CVE-2026-63800
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-416
Use After Free
