CVE-2026-63800
published 2026-07-19CVE-2026-63800: In the Linux kernel, the following vulnerability has been resolved: pNFS: Fix use-after-free in pnfs_update_layout() When hitting the NFS_LAYOUT_RETURN branch…
PriorityP348critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.50%
40.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
pNFS: Fix use-after-free in pnfs_update_layout()
When hitting the NFS_LAYOUT_RETURN branch in pnfs_update_layout(),
the code calls pnfs_prepare_to_retry_layoutget(lo). If it succeeds,
pnfs_put_layout_hdr(lo) is called before trace_pnfs_update_layout(),
which still references 'lo'. This results in a use-after-free when the
tracepoint accesses lo's fields.
Fix this by moving the tracepoint call before pnfs_put_layout_hdr(lo).
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 06f58dbc49a23c99e5c0f246879ed16667f7bf8f < 4ad8b9a85dbf57ca532ee9e65ad7e6498bfbbf98 | 4ad8b9a85dbf57ca532ee9e65ad7e6498bfbbf98 |
| linux | linux | >= 2c8d5fc37fe2384a9bdb6965443ab9224d46f704 < 1f24b8302c77dcaf79c64c073877a3b9f4dd25d2 | 1f24b8302c77dcaf79c64c073877a3b9f4dd25d2 |
| linux | linux | >= 2c8d5fc37fe2384a9bdb6965443ab9224d46f704 < 9c0fb5c09ae5bd68dc0038692af8127029cb0385 | 9c0fb5c09ae5bd68dc0038692af8127029cb0385 |
| linux | linux | >= 2c8d5fc37fe2384a9bdb6965443ab9224d46f704 < 7e37e9b3e82ade881e1798e2f4fcc54aff7793c1 | 7e37e9b3e82ade881e1798e2f4fcc54aff7793c1 |
| linux | linux | >= 2c8d5fc37fe2384a9bdb6965443ab9224d46f704 < 2883ddd7542b4437a2ab4908fe2773f690e20889 | 2883ddd7542b4437a2ab4908fe2773f690e20889 |
| linux | linux | >= 2c8d5fc37fe2384a9bdb6965443ab9224d46f704 < 200e7637f4d6a1342987045eea72641524f909dc | 200e7637f4d6a1342987045eea72641524f909dc |
| linux | linux | >= 2c8d5fc37fe2384a9bdb6965443ab9224d46f704 < 9645aaf689aff57427ece3b9fa47d5b5399417f4 | 9645aaf689aff57427ece3b9fa47d5b5399417f4 |
| linux | linux | >= 2c8d5fc37fe2384a9bdb6965443ab9224d46f704 < 13e198a90ca4050f4bee8a3f23680389a6563ccc | 13e198a90ca4050f4bee8a3f23680389a6563ccc |
| linux | linux | >= 5.10.9 < 5.10.260 | 5.10.260 |
| linux | linux | >= 5.4.91 < 5.5 | 5.5 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 5.10.9 < 5.10.260 | 5.10.260 |
| linux | linux_kernel | >= 5.11.1 < 5.15.211 | 5.15.211 |
| linux | linux_kernel | >= 5.16 < 6.1.177 | 6.1.177 |
| linux | linux_kernel | >= 5.4.91 < 5.5 | 5.5 |
| linux | linux_kernel | >= 6.13 < 6.18.38 | 6.18.38 |
| linux | linux_kernel | >= 6.19 < 7.1.3 | 7.1.3 |
| linux | linux_kernel | >= 6.2 < 6.6.144 | 6.6.144 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In the Linux kernel, the following vulnerability has been resolved: pNFS: Fix use-after-free in pnfs_update_layout() When hitting the NFS_LAYOUT_RETURN branch in pnfs_update_layout(), the code calls
ghsa_unreviewed·2026-07-19
CVE-2026-63800 [CRITICAL] In the Linux kernel, the following vulnerability has been resolved: pNFS: Fix use-after-free in pnfs_update_layout() When hitting the NFS_LAYOUT_RETURN branch in pnfs_update_layout(), the code calls
In the Linux kernel, the following vulnerability has been resolved:
pNFS: Fix use-after-free in pnfs_update_layout()
When hitting the NFS_LAYOUT_RETURN branch in pnfs_update_layout(),
the code calls pnfs_prepare_to_retry_layoutget(lo). If it succeeds,
pnfs_put_layout_hdr(lo) is called before trace_pnfs_update_layout(),
which still references 'lo'. This results in a use-after-free when the
tracepoint accesses lo's fields.
Fix this by moving the tracepoint call before pnfs_put_layout_hdr(lo).
Red Hat
kernel: pNFS: Fix use-after-free in pnfs_update_layout()
vendor_redhat·2026-07-19·CVSS 9.8
CVE-2026-63800 [CRITICAL] CWE-825 kernel: pNFS: Fix use-after-free in pnfs_update_layout()
kernel: pNFS: Fix use-after-free in pnfs_update_layout()
In the Linux kernel, the following vulnerability has been resolved:
pNFS: Fix use-after-free in pnfs_update_layout()
When hitting the NFS_LAYOUT_RETURN branch in pnfs_update_layout(),
the code calls pnfs_prepare_to_retry_layoutget(lo). If it succeeds,
pnfs_put_layout_hdr(lo) is called before trace_pnfs_update_layout(),
which still references 'lo'. This results in a use-after-free when the
tracepoint accesses lo's fields.
Fix this by moving the tracepoint call before pnfs_put_layout_hdr(lo).
A flaw was found in the Linux kernel's parallel Network File System (pNFS) component. An issue in the `pnfs_update_layout()` function causes a use-after-free vulnerability due to incorrect ordering of memory management operations. This flaw can
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/13e198a90ca4050f4bee8a3f23680389a6563ccchttps://git.kernel.org/stable/c/1f24b8302c77dcaf79c64c073877a3b9f4dd25d2https://git.kernel.org/stable/c/200e7637f4d6a1342987045eea72641524f909dchttps://git.kernel.org/stable/c/2883ddd7542b4437a2ab4908fe2773f690e20889https://git.kernel.org/stable/c/4ad8b9a85dbf57ca532ee9e65ad7e6498bfbbf98https://git.kernel.org/stable/c/7e37e9b3e82ade881e1798e2f4fcc54aff7793c1https://git.kernel.org/stable/c/9645aaf689aff57427ece3b9fa47d5b5399417f4https://git.kernel.org/stable/c/9c0fb5c09ae5bd68dc0038692af8127029cb0385
2026-07-19
Published