In the Linux kernel, the following vulnerability has been resolved:
pNFS: Fix use-after-free in pnfs_update_layout()
When hitting the NFS_LAYOUT_RETURN branch in pnfs_update_layout(),
the code calls pnfs_prepare_to_retry_layoutget(lo). If it succeeds,
pnfs_put_layout_hdr(lo) is called before trace_pnfs_update_layout(),
which still references 'lo'. This results in a use-after-free when the
tracepoint accesses lo's fields.
Fix this by moving the tracepoint call before pnfs_put_layout_hdr(lo).
References
Configurations
Configuration 1 (hide)
|
History
29 Jul 2026, 20:12
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:5.11:rc5:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:5.11:rc6:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:5.11:rc4:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:5.11:-:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:5.11:rc7:*:*:*:*:*:* |
|
| CWE | CWE-416 | |
| References | () https://git.kernel.org/stable/c/13e198a90ca4050f4bee8a3f23680389a6563ccc - Patch | |
| References | () https://git.kernel.org/stable/c/1f24b8302c77dcaf79c64c073877a3b9f4dd25d2 - Patch | |
| References | () https://git.kernel.org/stable/c/200e7637f4d6a1342987045eea72641524f909dc - Patch | |
| References | () https://git.kernel.org/stable/c/2883ddd7542b4437a2ab4908fe2773f690e20889 - Patch | |
| References | () https://git.kernel.org/stable/c/4ad8b9a85dbf57ca532ee9e65ad7e6498bfbbf98 - Patch | |
| References | () https://git.kernel.org/stable/c/7e37e9b3e82ade881e1798e2f4fcc54aff7793c1 - Patch | |
| References | () https://git.kernel.org/stable/c/9645aaf689aff57427ece3b9fa47d5b5399417f4 - Patch | |
| References | () https://git.kernel.org/stable/c/9c0fb5c09ae5bd68dc0038692af8127029cb0385 - Patch | |
| First Time |
Linux linux Kernel
Linux |
20 Jul 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
19 Jul 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-19 12:16
Updated : 2026-07-29 20:12
NVD link : CVE-2026-63800
Mitre link : CVE-2026-63800
CVE.ORG link : CVE-2026-63800
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-416
Use After Free
