Impact
In the Linux kernel, the Sun RPC service failed to properly distribute its worker threads across CPU‑specific pools when the configured number of threads was less than the number of available pools. An incoming RPC request is routed to the pool associated with the CPU handling the transport. If that pool has no threads, the request stays queued forever because no worker can pick it up, resulting in an indefinitely hanging connection. This flaw is a classic instance of resource starvation (CWE‑821) and results in a denial of service for clients that rely on the RPC service.
Affected Systems
Any Linux kernel installation that runs the Sun RPC NFS server in NUMA‑aware mode (pernode or percpu) with fewer service threads than CPU pools may be affected. The report does not list specific kernel versions, so any kernel prior to the fix that uses the vulnerable svc_pool_for_cpu logic could suffer the hang. Linux distributions shipping earlier kernel versions are therefore potentially vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.5 and an EPSS score of less than 1 %. It is not listed in the CISA KEV catalog. An attacker can exploit the flaw by sending a series of RPC requests from a client that targets the vulnerable NFS mount; when a request is routed to an empty pool the connection never completes, causing the server to consume resources and degrade availability. Based on the description, it is inferred that the attack vector would likely involve remote network traffic to the Sun RPC service.
OpenCVE Enrichment
Debian DSA