Affects Linux kernel NFS server (widely deployed core OS component); can crash or corrupt kernels across enterprises.
CVE-2026-53398
Linux kernel NFS server decode bug can cause remote kernel memory corruption or crash.
Is CVE-2026-53398 being exploited?
Not confirmed. CVE-2026-53398 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.54% probability of exploitation in the next 30 days.
How severe is CVE-2026-53398?
CVE-2026-53398 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-53398?
Yes. A fix has been recorded for CVE-2026-53398. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-53398 affect?
CVE-2026-53398 affects Linux kernel (nfsd NFSv4 server). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-53398?
Apply vendor/upstream kernel security update or backport immediately and restart NFS service.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Malformed NFSv4 SECINFO_NO_NAME requests can trigger use of uninitialized pointer, causing kernel memory corruption, panic, or potential privilege escalation.
Immediate action required
- affected>= 5e76b25d7cc82c148d391c0c43b884e6427cb302 and < 8836405abdc53ca3dd5fc68b2cf6f8f012fad011
- affected>= 07b68ff5c71cf4ed5443016d8eb116863c0a4d88 and < 49de5d31dd8fdebf78bdeaf196b0ca5cd5c75439
- affected>= 3fdc546462348b8a497c72bc894e0cde9f10fc40 and < 5ec37edcb534f3fc92304be236d37f08e6545585
- affected>= 3fdc546462348b8a497c72bc894e0cde9f10fc40 and < 1e04be34cafae119e82bcaccd6d28a20f72a3647
- affected>= 3fdc546462348b8a497c72bc894e0cde9f10fc40 and < 161d1aaeb04d620d3692639700512bb5038c1e10
- affected>= 3fdc546462348b8a497c72bc894e0cde9f10fc40 and < c8a24effd96d4779e2ad779654682304491c55a5
- affected>= 3fdc546462348b8a497c72bc894e0cde9f10fc40 and < 46eb17d45be69d28c7a23ea03283b207426a8232
- affected>= 3fdc546462348b8a497c72bc894e0cde9f10fc40 and < 9e18e83b8846a5c3fe13fc8a464b4865d33996c6
- affected>= 5.10.220 and < 5.10.260
- affected>= 5.15.154 and < 5.15.211
- affected6.1
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.