Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-53399

9.8 · CRITICAL
Published Jul 19, 2026 linux CWE-476

Overview

CVE-2026-53399 is a critical-severity vulnerability affecting linux linux_kernel. It was published on July 19, 2026 and has a CVSS 3.1 base score of 9.8 (CRITICAL).

This vulnerability has a CVSS 3.1 base score of 9.8, rated CRITICAL. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

nfsd: release layout stid on setlease failure

nfs4_alloc_stid() publishes the new stid into cl->cl_stateids via

idr_alloc_cyclic() under cl_lock before returning to

nfsd4_alloc_layout_stateid(). When nfsd4_layout_setlease() then

fails, the error path frees the layout stateid directly with

kmem_cache_free() without ever calling idr_remove(), leaving the

IDR slot pointing at freed slab memory. Any subsequent IDR walker

(states_show, client teardown) dereferences the dangling pointer.

The correct teardown for an IDR-published stid is nfs4_put_stid(),

which removes the IDR slot under cl_lock, dispatches sc_free

(nfsd4_free_layout_stateid) to release ls->ls_file via

nfsd4_close_layout(), and drops the nfs4_file reference in its

tail.

A second issue blocks that switch: nfsd4_free_layout_stateid()

unconditionally inspects ls->ls_fence_work via

delayed_work_pending() under ls_lock, but

INIT_DELAYED_WORK(&ls->ls_fence_work,

Remediation

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
linux linux_kernel >= 4.0, < 5.10.261 Affected

Frequently Asked Questions

What is CVE-2026-53399?

CVE-2026-53399 is a critical-severity vulnerability affecting linux linux_kernel. It was published on July 19, 2026 and has a CVSS 3.1 base score of 9.8 (CRITICAL).

How severe is CVE-2026-53399?

This vulnerability has a CVSS 3.1 base score of 9.8, rated CRITICAL. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2026-53399?

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-53399?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-53399 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.

Browse by year 2026