Impact
The kernel contains a logic flaw in the NFS daemon whereby a revocation loop fails to advance because a status field is never set. As a result, the same layout reference identifier is repeatedly found and the revoker is trapped in an infinite loop, causing the NFS service to hang and deny further legitimate traffic. The weakness is a classic infinite loop flaw that can lead to a persistent denial of service.
Affected Systems
The vulnerability affects the Linux kernel on all distributions that ship with the unpatched NFS daemon. No specific version information is provided in the disclosure, so any installation running a kernel containing the bug may be impacted.
Risk and Exploitability
The EPSS score is reported as less than 1%, indicating a low likelihood that this vulnerability will be actively exploited, and it is not listed in the CISA KEV catalog. Nonetheless, the CVSS score of 5.5 classifies it as a moderate severity vulnerability. The infinite loop can cause the NFS daemon to hang, leading to a denial of service. The likely attack vector is remote: an NFS client that initiates a revocation request can trigger the loop and exhaust resources on the server. Because the flaw only affects the NFS server's revocation logic, addressing it with a kernel update mitigates the risk.
OpenCVE Enrichment
Ubuntu USN