Impact
The kernel function responsible for initializing service pools neglected to check the return status of per‑CPU counter allocation. When an allocation failed, the counter pointer remained NULL, yet the partially constructed service was accepted by the NFS subsystem. Subsequent use of the counter in hot‑path operations silently accessed a NULL per‑CPU counter, corrupting arbitrary kernel data. This flaw can lead to kernel instability, memory corruption, or denial of service if exploited. The flaw is reachable only by a local administrator under memory pressure or fault injection; a remote peer cannot induce the bad state on its own.
Affected Systems
All Linux kernel releases that include the vulnerable svc_create implementation are affected; the specific version ranges are not checks percpu_counter_init return values is vulnerable. The flaw resides in NFS, lockd, and the NFS callback service components of the kernel.
Risk and Exploitability
The vulnerability has a CVSS score of 8.1, which indicates high severity. The EPSS score is reported as < 1%, meaning the exploitation likelihood is low but not zero. The flaw is not in the CISA KEV catalog. Attacking this bug requires a local administrator to trigger a per‑CPU allocation failure during RPC server startup, for example by exhausting memory or injecting faults. code paths that increment the uninitialized counter will silently access a NULL per‑CPU counter, corrupting arbitrary kernel data. This can lead to kernel panic, memory corruption. Remote exploitation is not possible under normal circumstances.
OpenCVE Enrichment
Debian DSA