Impact
The lockd NFS lock daemon contains a use‑after‑free flaw in nlm_traverse_files. The code increments a reference, but the pointer to the next file is not pinned. A concurrent nlm_release_file can free that next file during the unlock window, and the iterator later dereferences freed memory, resulting in kernel memory corruption. An attacker that can trigger the race could cause a kernel crash or potentially execute arbitrary code at ring‑zero if the freed memory is reused maliciously.
Affected Systems
The vulnerability affects all Linux kernel builds that include the lockd component prior to the commit that introduces the pinning logic fix. Vendors listed as Linux:Linux indicate that any distribution using the upstream Linux kernel is potentially impacted. No specific release numbers are supplied, so the risk applies to any kernel running before the patch is applied, regardless of version.
Risk and Exploitability
Based on the description, the likely attack vector is a race condition that a local or privileged process can orchestrate against the lockd NFS lock daemon. The CVSS score of 9.8 signals critical severity, while the EPSS score of less than 1% indicates a low probability of exploitation at this time. The flaw requires a carefully timed race, and based on the description it is inferred that the attack surface is largely limited to processes that can manipulate NFS locks. The vulnerability is not listed in the CISA KEV catalog, yet its high influence on kernel integrity warrants prompt action. If an attacker succeeds, the resulting kernel memory corruption can lead to a crash, denial of service, or a privilege escalation pathway to full system compromise.
OpenCVE Enrichment
Debian DSA