Impact
A race condition in the Linux kernel’s NFS callback subsystem allows a backchannel receive to complete while the callback service is being torn down, service that is about to be freed. This flaw can lead to a leaked reference and a possible use‑after‑free, corrupting kernel memory or causing a crash. The high CVSS score of 9.8 reflects significant denial of service or compromise that may be triggered by controlling NFS traffic, which is a component‑level orchestration defect (CWE‑911).
Affected Systems
All Linux kernel releases incorporate this flaw as it resides in core kernel logic; no specific version range is delineated by the CNA.
Risk and Exploitability
The EPSS score of < 1 % indicates a very low probability of exploitation. The CVSS score of 9.8 signifies extremely high severity, with the potential to cause a kernel crash or denial of service. Attackers would need to influence NFS client traffic while the callback service is shutting down, which may require local or privileged access or a compromised NFS client. The vulnerability is not listed in the CISA KEV catalog and no public exploit has been reported.
OpenCVE Enrichment