Impact
A NULL pointer dereference occurs in the Linux kernel's NFS client lock subsystem when the allocation of a lockowner fails during nlmclnt_locks_init_private. The failure to install the lockowner initialized file_lock, causing nlmclnt_locks_release_private to dereference fl->fl_u.nfs_fl.owner, which was never set. This kernel crash produces a denial‑of‑service by bringing the system offline.
Affected Systems
Any Linux system that is running a kernel version containing the vulnerable lockd code is affected. The vulnerability exists until the patch commit that cleared the lock operations on allocation failure is applied. Systems with updated kernels that include the fix are not vulnerable.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. The EPSS score of < 1% reflects a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The flaw is triggered by a failed memory allocation in the NFS client lock code, so the likely attack vector is local or requires an NFS client that can force such failures, as inferred from the kernel context. Due to the kernel‑level nature of the fault, exploitation would need such a trigger, making the overall risk moderate.
OpenCVE Enrichment
Debian DSA