Impact
A stack buffer overflow occurs in the 9P protocol implementation of NFS-Ganesha when the server fails to enforce the maximum number of path components defined by the 9P protocol. A specially crafted TWALK request containing thousands of path components overwrites a fixed-size stack buffer during response construction. This can cause a crash or, depending on the environment, remote code execution. The flaw is a classic stack-based buffer overflow (CWE-121).
Affected Systems
Any NFS-Ganesha server that exposes the 9P protocol listener is affected. No specific version information was provided, so all deployments are potentially vulnerable until patched.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Because authentication is not enforced on the 9P listener, any network client can send the malicious TWALK request, making the attack vector local network or over the Internet if the listener is exposed. The exploit requires only a crafted message; no privileged access or persistence is needed to trigger the overflow.
OpenCVE Enrichment