CVE-2026-53393
CVE CVE-2026-53393EUVD EUVD-2026-45515Published 2026-07-19T12:01:56.000ZLast changed 2026-07-24T14:33:59.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: nfsd: reset write verifier on deferred writeback errors nfsd_vfs_write() and nfsd_commit() both call filemap_check_wb_err() to detect deferred writeback errors, but neither rotates the server's write verifier (nn->writeverf) when this check fails. Every other durable-storage-failure path in these functions calls commit_reset_write_verifier() before returning an error. The missing rotation means clients holding UNSTABLE write data under the current verifier will COMMIT, receive the unchanged verifier back, and conclude their data is durable — silently dropping data that failed writeback. This violates the UNSTABLE+COMMIT durability contract (RFC 1813 §3.3.7, RFC 8881 §18.32). Add commit_reset_write_verifier() calls at both filemap_check_wb_err() error sites, matching the pattern used by adjacent error paths in the same functions. The helper already filters -EAGAIN and -ESTALE internally, so the calls are unconditionally safe.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 555dbf1a9aac6d3150c8b52fa35f768a692f4eeb <2090b05803faab8a9fa62fbff871007862cac1b7; patch: 6.18.38; 5.10.124 <5.10.261; 3145fe0ebb16e1715ad541a301bc6675c8375fcd <bc2baca02ec56da7707a74ed5d340b0a1dff1841; 555dbf1a9aac6d3150c8b52fa35f768a692f4eeb <43b65d2997963e80e8d8d86520bcb1e0751227de; 555dbf1a9aac6d3150c8b52fa35f768a692f4eeb <b027cca33c97354149fcc0ddeede4525c41093cd; patch: 6.12.95; 5.17; patch: 5.10.261; f14816f2f928c560d28ba344af689f56efcd6f55 <b8e5894e56cff70fa245628fe16f0ad6367f8090; patch: 6.1.178; 555dbf1a9aac6d3150c8b52fa35f768a692f4eeb <4367afc119c51e17a616f6908772b7e2c2c4013f; patch: 7.1.3; patch: 0; patch: 6.6.145; 555dbf1a9aac6d3150c8b52fa35f768a692f4eeb <1dd664b39774a9c89b72de8e59bf9ef4b3aaff2e; patch: 7.2-rc1; patch: 5.15.212; 5.15.49 <5.15.212; 555dbf1a9aac6d3150c8b52fa35f768a692f4eeb <666e837b247fcadf2d8d508b9b0e49d720393eb4
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.