Impact
A race condition in the 9P protocol implementation of NFS‑Ganesha allows an attacker to perform a write operation concurrently with a close operation on the same file identifier, freeing it while another thread continues to use it. This results in a use‑after‑free that lets attacker‑controlled data be written into freed heap memory, which can cause a crash or enable arbitrary code execution. The flaw is a classic CWE‑416 situation.
Affected Systems
The affected product is the NFS‑Ganesha server, specifically its 9P protocol handler. No specific version numbers are listed, so the vulnerability may affect all versions that have not been patched for the 9P use‑after‑free issue.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.1, indicating high severity. No EPSS score is available, and it is not listed in the CISA KEV catalog. Because the 9P handler lacks authentication, the flaw is reachable to any network client that can reach the 9P listener. An attacker can trigger the race condition remotely without credentials, making exploitation straightforward if they can observe two simultaneous 9P operations on the same file identifier.
OpenCVE Enrichment