Impact
A race condition exists in the Linux kernel’s SUNRPC TLS handshake handling where rising references to the underlying transport are released prematurely when a cancellation or timeout occurs. The callback that stores error information can run after the transport has been freed, potentially leading to a use‑after‑free memory bug and a kernel panic.
Affected Systems
This flaw affects the Linux kernel’s SUNRPC implementation; specific vendor and product details are listed as Linux Linux. No particular kernel versions are named in the provided data, so all versions before the commit that introduced the fix are considered vulnerable.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. The EPSS score of less than 1% indicates a very low but nonzero probability of exploitation, and the vulnerability is not listed in CISA KEV. The likely attack vector is a malicious or misbehaving client initiating a remote procedure call that triggers a TLS handshake cancellation or timeout while the kernel is processing the handshake, thereby exploiting the race condition. Successful exploitation could terminate the RPC process or cause a kernel panic, providing a denial of service to the target system.
OpenCVE Enrichment
Debian DSA