Answer in brief
CVE-2026-63800 records a Unknown severity vulnerability in pNFS: Fix use-after-free in pnfs_update_layout(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-63800 records a Unknown severity vulnerability in pNFS: Fix use-after-free in pnfs_update_layout(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=06f58dbc49a23c99e5c0f246879ed16667f7bf8f <4ad8b9a85dbf57ca532ee9e65ad7e6498bfbbf98 || >=2c8d5fc37fe2384a9bdb6965443ab9224d46f704 <1f24b8302c77dcaf79c64c073877a3b9f4dd25d2 || >=2c8d5fc37fe2384a9bdb6965443ab9224d46f704 <9c0fb5c09ae5bd68dc0038692af8127029cb0385 || >=2c8d5fc37fe2384a9bdb6965443ab9224d46f704 <7e37e9b3e82ade881e1798e2f4fcc54aff7793c1 || >=2c8d5fc37fe2384a9bdb6965443ab9224d46f704 <2883ddd7542b4437a2ab4908fe2773f690e20889 || >=2c8d5fc37fe2384a9bdb6965443ab9224d46f704 <200e7637f4d6a1342987045eea72641524f909dc || >=2c8d5fc37fe2384a9bdb6965443ab9224d46f704 <9645aaf689aff57427ece3b9fa47d5b5399417f4 || >=2c8d5fc37fe2384a9bdb6965443ab9224d46f704 <13e198a90ca4050f4bee8a3f23680389a6563ccc || aa2399f55eff4ec78330bb6fe55f9df53e5cae0c || >=5.10.9 <5.10.260 || >=5.4.91 <5.5 | 4ad8b9a85dbf57ca532ee9e65ad7e6498bfbbf98, 1f24b8302c77dcaf79c64c073877a3b9f4dd25d2, 9c0fb5c09ae5bd68dc0038692af8127029cb0385, 7e37e9b3e82ade881e1798e2f4fcc54aff7793c1, 2883ddd7542b4437a2ab4908fe2773f690e20889, 200e7637f4d6a1342987045eea72641524f909dc, 9645aaf689aff57427ece3b9fa47d5b5399417f4, 13e198a90ca4050f4bee8a3f23680389a6563ccc, 5.10.260, 5.5 |
| Linux/Linuxgeneric | 5.11 | Not reported |
Published upstream
Jul 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: pNFS: Fix use-after-free in pnfs_update_layout() When hitting the NFS_LAYOUT_RETURN branch in pnfs_update_layout(), the code calls pnfs_prepare_to_retry_layoutget(lo). If it succeeds, pnfs_put_layout_hdr(lo) is called before trace_pnfs_update_layout(), which still references 'lo'. This results in a use-after-free when the tracepoint accesses lo's fields. Fix this by moving the tracepoint call before pnfs_put_layout_hdr(lo).
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=06f58dbc49a23c99e5c0f246879ed16667f7bf8f <4ad8b9a85dbf57ca532ee9e65ad7e6498bfbbf98 || >=2c8d5fc37fe2384a9bdb6965443ab9224d46f704 <1f24b8302c77dcaf79c64c073877a3b9f4dd25d2 || >=2c8d5fc37fe2384a9bdb6965443ab9224d46f704 <9c0fb5c09ae5bd68dc0038692af8127029cb0385 || >=2c8d5fc37fe2384a9bdb6965443ab9224d46f704 <7e37e9b3e82ade881e1798e2f4fcc54aff7793c1 || >=2c8d5fc37fe2384a9bdb6965443ab9224d46f704 <2883ddd7542b4437a2ab4908fe2773f690e20889 || >=2c8d5fc37fe2384a9bdb6965443ab9224d46f704 <200e7637f4d6a1342987045eea72641524f909dc || >=2c8d5fc37fe2384a9bdb6965443ab9224d46f704 <9645aaf689aff57427ece3b9fa47d5b5399417f4 || >=2c8d5fc37fe2384a9bdb6965443ab9224d46f704 <13e198a90ca4050f4bee8a3f23680389a6563ccc || aa2399f55eff4ec78330bb6fe55f9df53e5cae0c || >=5.10.9 <5.10.260 || >=5.4.91 <5.5 | 4ad8b9a85dbf57ca532ee9e65ad7e6498bfbbf98, 1f24b8302c77dcaf79c64c073877a3b9f4dd25d2, 9c0fb5c09ae5bd68dc0038692af8127029cb0385, 7e37e9b3e82ade881e1798e2f4fcc54aff7793c1, 2883ddd7542b4437a2ab4908fe2773f690e20889, 200e7637f4d6a1342987045eea72641524f909dc, 9645aaf689aff57427ece3b9fa47d5b5399417f4, 13e198a90ca4050f4bee8a3f23680389a6563ccc, 5.10.260, 5.5 |
| Linux/Linuxgeneric | 5.11 | Not reported |
Published upstream
Jul 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: pNFS: Fix use-after-free in pnfs_update_layout() When hitting the NFS_LAYOUT_RETURN branch in pnfs_update_layout(), the code calls pnfs_prepare_to_retry_layoutget(lo). If it succeeds, pnfs_put_layout_hdr(lo) is called before trace_pnfs_update_layout(), which still references 'lo'. This results in a use-after-free when the tracepoint accesses lo's fields. Fix this by moving the tracepoint call before pnfs_put_layout_hdr(lo).
Quoted source text, attributed separately from HOL analysis.