Impact
This vulnerability is a use‑after‑free in the Linux kernel sunrpc module caused by a stale clnt->pipefs_sb pointer that is not refreshed during pipefs mount events or cleared during unmounts; when rpc_clnt_remove_pipedir compares the current superblock against this outdated pointer it skips cleanup, leaving dentries that point to freed rpc_clnt structures, which can later be dereferenced by rpc_info_open or rpc_show_info, resulting in kernel memory corruption.
Affected Systems
All Linux kernel installations in which the sunrpc component is available and that have not incorporated commit 932a8cf6abb2b2f8677b79153a823108d8861fe2 – effectively every distribution that ships the default sunrpc module before the patch was applied.
Risk and Exploitability
The CVSS score of 4.1 and an EPSS score below 1% indicate a low likelihood of exploitation, and the vulnerability is not listed in the C, it is inferred that an attacker would need to trigger a pipefs mount or unmount event or generate relevant RPC traffic to create the stale pointer condition, but no specific privilege escalation or remote code execution pathways are detailed by the advisory.
OpenCVE Enrichment
Debian DSA