A Linux kernel vulnerability affecting the pNFS subsystem can lead to kernel compromise across many Linux systems and infrastructure; widespread impact on servers and appliances.
CVE-2026-63800
Linux kernel pNFS use-after-free in pnfs_update_layout allows kernel compromise
Is CVE-2026-63800 being exploited?
Not confirmed. CVE-2026-63800 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.53% probability of exploitation in the next 30 days.
How severe is CVE-2026-63800?
CVE-2026-63800 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-63800?
Yes. A fix has been recorded for CVE-2026-63800. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-63800 affect?
CVE-2026-63800 affects Linux kernel (pNFS subsystem), Systems running NFS/pNFS clients or servers. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-63800?
Install vendor/kernel patch immediately; restrict pNFS access until patched.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Crafted pNFS requests can trigger a kernel use-after-free, causing crashes or enabling arbitrary kernel code execution/privilege escalation.
Immediate action required
- affected>= 06f58dbc49a23c99e5c0f246879ed16667f7bf8f and < 4ad8b9a85dbf57ca532ee9e65ad7e6498bfbbf98
- affected>= 2c8d5fc37fe2384a9bdb6965443ab9224d46f704 and < 1f24b8302c77dcaf79c64c073877a3b9f4dd25d2
- affected>= 2c8d5fc37fe2384a9bdb6965443ab9224d46f704 and < 9c0fb5c09ae5bd68dc0038692af8127029cb0385
- affected>= 2c8d5fc37fe2384a9bdb6965443ab9224d46f704 and < 7e37e9b3e82ade881e1798e2f4fcc54aff7793c1
- affected>= 2c8d5fc37fe2384a9bdb6965443ab9224d46f704 and < 2883ddd7542b4437a2ab4908fe2773f690e20889
- affected>= 2c8d5fc37fe2384a9bdb6965443ab9224d46f704 and < 200e7637f4d6a1342987045eea72641524f909dc
- affected>= 2c8d5fc37fe2384a9bdb6965443ab9224d46f704 and < 9645aaf689aff57427ece3b9fa47d5b5399417f4
- affected>= 2c8d5fc37fe2384a9bdb6965443ab9224d46f704 and < 13e198a90ca4050f4bee8a3f23680389a6563ccc
- affectedaa2399f55eff4ec78330bb6fe55f9df53e5cae0c
- affected>= 5.10.9 and < 5.10.260
- affected>= 5.4.91 and < 5.5
- affected5.11
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.