VDB

CVE-2026-43394

CVE-2026-43394 PUBLISHED

In the Linux kernel, the following vulnerability has been resolved: nfsd: Fix cred ref leak in nfsd_nl_listener_set_doit(). nfsd_nl_listener_set_doit() uses get_current_cred() without put_cred(). As we can see from other callers, svc_xprt_create_from_sa() does not require the extra refcount. nfsd_nl_listener_set_doit() is always in the process context, sendmsg(), and current->cred does not go away. Let's use current_cred() in nfsd_nl_listener_set_doit().

EPSS 0.01% · 2.2th percentile

Risk Scores

EPSS Score
0.01%
2.2th percentile

Affected Products

VendorProductVersions
linuxlinux_kernel6.10, 6.10, 6.10
LinuxLinux16a471177496c8e04a9793812c187a2c1a2192fa, 16a471177496c8e04a9793812c187a2c1a2192fa, 6.10

Timeline

  • May 8, 2026 CVE Published
  • May 8, 2026 CVE Updated
  • May 8, 2026 Security Advisory
  • May 18, 2026 EPSS Score
  • May 19, 2026 EPSS Score
  • May 20, 2026 EPSS Score
  • May 21, 2026 EPSS Score
  • May 22, 2026 EPSS Score
  • May 23, 2026 EPSS Score
  • May 24, 2026 EPSS Score
  • May 25, 2026 EPSS Score
  • May 26, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›