External risk intelligence

Linux Kernel NFSv4.1 Uninitialized Memory Dereference

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-90104

This vulnerability exists within the Linux kernel NFSv4.1 callback handling logic. NFS (Network File System) is typically deployed within internal, trusted networks to share files between servers and clients. It is not designed to be exposed to the public internet, and such exposure would be a significant misconfiguration.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability in the Linux kernel's NFSv4.1 component could allow for unauthorized access and modification of data due to an uninitialized pointer issue during callback processing. The primary concern is to confirm if this specific NFSv4.1 functionality is in use and exposed externally, as it is typically an internal network service.

  • Uninitialized memory in NFSv4.1 processing.
  • Matters if internal NFS is exposed externally.
  • Confirm relevance; internal systems are main concern.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted network traffic to a Linux system running an affected NFSv4.1 service. This traffic would target the callback handling mechanism, leading to the improper deallocation of memory. Successful exploitation could allow an attacker to gain control over critical system functions.

  • Network access to NFSv4.1 service required.
  • Specially crafted network traffic triggers vulnerability.
  • Uninitialized memory use can lead to system compromise.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in the Linux kernel's NFSv4.1 callback handling could allow an unauthenticated attacker to trigger a kernel memory disclosure and denial-of-service condition. When processing specific NFSv4.1 callback sequences, an uninitialized memory pointer may be passed to a deallocation function, leading to the exposure of kernel memory contents and a system crash.

  • Kernel memory.
  • Uninitialized pointer dereference.
  • System crash or memory disclosure.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the Linux kernel's NFSv4.1 callback handling is likely to impact infrastructure or platform teams responsible for managing Linux servers and NFS services. The first practical step is to identify all Linux systems running NFSv4.1, assess their network exposure, and determine business criticality to prioritize remediation efforts with the accountable system owner.

  • Infrastructure or Platform Teams own remediation.
  • Verify NFSv4.1 exposure and criticality.
  • Plan coordinated maintenance for patching.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Linux kernel component affected by CVE-2026-90104?

This vulnerability resides within the NFSv4.1 component of the Linux kernel. NFS, or Network File System, is a distributed file system protocol that allows a user on a client computer to access files over a network as if they were on local storage. It is a fundamental tool for sharing data across servers and workstations in networked environments.

How does this uninitialized memory issue trigger a security risk?

The flaw is an uninitialized pointer dereference. When the system processes specific NFSv4.1 callback sequences, it attempts to free memory using a pointer that was never properly initialized. This can result in the system attempting to release stale or invalid data, which may lead to unintended kernel memory disclosure or a system crash.

Can any network traffic trigger this vulnerability?

No. The vulnerability is triggered specifically when the kernel processes crafted callback sequences within the NFSv4.1 protocol. Simply having NFS traffic present is not enough; the attacker must be able to influence the specific callback arguments that cause the kernel to mishandle the uninitialized memory pointer.

Why should I worry if my NFS service is internal?

According to Halo Surface Signal, this vulnerability is very unlikely to affect you if your NFS services are restricted to internal, trusted networks. The risk significantly increases only if your NFSv4.1 implementation is misconfigured and exposed to the public internet, where unauthorized parties could send the necessary traffic to target the service.

What is the first step for teams managing affected servers?

Your initial priority is to identify every Linux system in your environment currently running the NFSv4.1 service. Once you have a complete list, verify which of those systems are accessible from external networks versus those kept purely internal. Coordinate with the relevant system owners to plan maintenance and patching based on the criticality of those specific assets.

References