CVE-2026-93211

Summary

In the Linux kernel, the following vulnerability has been resolved:

nfsd: initialize DRC hash table before registering shrinker

shrinker_register() precedes the INIT_LIST_HEAD loop and the drc_hashsize store. On weakly-ordered architectures (arm64, ppc), a shrinker scan can observe drc_hashsize before the bucket list heads are initialized, causing a NULL deref in the DRC shrinker callback.

Move bucket initialization and the drc_hashsize store before shrinker_register() so the hash table is fully initialized before it becomes visible to the shrinker.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux8eea99a81c6f67c08fedd7db2ccd09aa93db69a7 < f060f43a67635dbb393bf5dcbfc3e8b9a44942cbaffected
LinuxLinux8eea99a81c6f67c08fedd7db2ccd09aa93db69a7 < b57bd8cb739cb3cf88bdb1a5903a42a707a5c282affected
LinuxLinux8eea99a81c6f67c08fedd7db2ccd09aa93db69a7 < 431c70ca5163c98c746f22f16cd58ca5aefec6dcaffected
LinuxLinux8eea99a81c6f67c08fedd7db2ccd09aa93db69a7 < b0c58934f5cc4f05b63ef6605dd10c1d0d489e88affected
LinuxLinux6.7affected
LinuxLinux0 < 6.7unaffected
LinuxLinux6.12.109 <= 6.12.*unaffected
LinuxLinux6.18.50 <= 6.18.*unaffected
LinuxLinux7.2.4 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References