A vulnerability, which was classified as very critical, has been found in Linux Kernel up to 6.12.95/6.18.38/7.1.2. This affects the function nfsd4_layout_setlease of the component Nfsd. The manipulation of the argument ls_fence_work leads to use after free.

This vulnerability is traded as CVE-2026-53399. It is possible to initiate the attack remotely. There is no exploit available.