CVE-2026-93211

medium

Description

In the Linux kernel, the following vulnerability has been resolved: nfsd: initialize DRC hash table before registering shrinker shrinker_register() precedes the INIT_LIST_HEAD loop and the drc_hashsize store. On weakly-ordered architectures (arm64, ppc), a shrinker scan can observe drc_hashsize before the bucket list heads are initialized, causing a NULL deref in the DRC shrinker callback. Move bucket initialization and the drc_hashsize store before shrinker_register() so the hash table is fully initialized before it becomes visible to the shrinker.

References

https://git.kernel.org/stable/c/f060f43a67635dbb393bf5dcbfc3e8b9a44942cb

https://git.kernel.org/stable/c/b57bd8cb739cb3cf88bdb1a5903a42a707a5c282

https://git.kernel.org/stable/c/b0c58934f5cc4f05b63ef6605dd10c1d0d489e88

https://git.kernel.org/stable/c/431c70ca5163c98c746f22f16cd58ca5aefec6dc

Details

Source: Mitre, NVD

Published: 2026-09-24

Updated: 2026-09-24

Risk Information

CVSS v2

Base Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00168