Impact
In the Linux kernel, a NULL dereference occurs during the allocation of a lockowner in nlmclnt_locks_init_private after a failed allocation, and subsequent cleanup dereferences an uninitialized pointer, causing a kernel crash. This fault results in a denial‑of‑service attack that destabilizes the entire system.
Affected Systems
Affected systems include all Linux installations that run a kernel containing the unpatched lock code. Any deployment that has not applied the patch that addresses the library lock allocation failure should be considered vulnerable.
Risk and Exploitability
With a CVSS score of 5.9 the vulnerability has moderate severity. The EPSS score is < 1%, indicating a very low exploitation probability, and it is not listed in the CISA KEV catalog. The bug can be triggered by either a local user with access to the file system or a remote NFS client that can cause the kernel to crash, placing it at moderate risk.
OpenCVE Enrichment