Impact
The vulnerability arises in the Linux kernel’s sunrpc module, where the /proc/net/rpc/use‑gss‑proxy file is exposed before the sn->gssp_lock mutex is initialized. This race window allows a user‑initiated write to lock a zero‑initialized mutex, which can corrupt or leak GSS client handles and potentially cause a denial of service. The likely attack vector is local, requiring an attacker to write during a brief window when the proc entry is published but the mutex has not yet been initialized; based on the description, it is inferred that preemption is necessary for the exploit to succeed, and no remote code execution or privilege escalation is provided by this flaw.
Affected Systems
All Linux kernel deployments that include the sunrpc module and compile the auth_rpcgss kernel module are affected. The flaw existed in every kernel version prior to sunrpc_init_net; no specific patch level is listed, so any unpatched kernel that exports /proc/net/rpc/use‑gss‑proxy before the initialization step is vulnerable.
Risk and Exploitability
The CVSS base score is 7.8, indicating high severity, and the EPSS score is less than 1%, meaning the likelihood of exploitation in the wild is very low but non‑zero. The vulnerability is not in the CISA KEV catalog. Because the exploit relies, widespread attacks are unlikely; however, immediate patching is advised to eliminate the race condition and protect against potential resource leaks or denial of service.
OpenCVE Enrichment
Debian DSA