Impact
An empty filehandle‑version count in an NFSv4 flexfiles layout was incorrectly accepted and used to allocate a ZERO_SIZE_PTR; when later dereferenced the kernel panics, which is a classic NULL pointer dereference (CWE‑476) that results in a denial of service without giving the attacker any privilege escalation or code execution ability.
Affected Systems
Linux kernels that include NFSv4 with flexfiles support are potentially affected. This includes any distribution that builds the kernel with that feature enabled. The vulnerability is present in kernels preceding the patch that lacks the zero‑count validation in ff_layout_alloc_lseg(). The affected system description here infers that common distributions may be exposed, but this inference is not explicitly stated in the CVE data.
Risk and Exploitability
With a CVSS score of 7.5 and an EPSS of <1 %, the vulnerability is high impact but low likelihood of widespread exploitation. The likely attack vector for an attacker who can reach the NFS service is to send a malformed flexfiles layout containing a zero filehandle‑version count, causing a NULL pointer dereference and kernel panic. This inference is based on the description of a malformed layout that triggers a KASAN null-pointer dereference, indicating no known public exploits.
OpenCVE Enrichment
Debian DLA
Debian DSA