Impact
The Linux kernel’s NFS daemon contains a race condition that can free a NFS client while it is still in use by a background cleanup routine, causing a use‑after‑free and possible kernel memory corruption. The flaw is a classic denial attacker could crash the kernel or corrupt memory to execute arbitrary code.
Affected Systems
All Linux distributions that ship the Linux kernel with an unpatched nfsd component are affected. The flaw resides in the NFSv4.0 server code; any kernel that includes the nfsd module without the commit that fixes the race condition is vulnerable. No specific kernel versions were listed, so any release prior to the fix should be considered at risk.
Risk and Exploitability
The CVSS vector scores a 9.8, placing it in the critical zone. The EPSS score is less than 1%, indicating that while exploitation is unlikely now, the high severity and lack of a publicly known exploit mean prompt action is warranted. The flaw can be triggered by writing to a client control file such as clients/<id>/ctl; based on the description it is inferred that this requires root or equivalent privileges, so the vulnerability is likely exploitable only by privileged users. The vulnerability does not appear in the CISA KEV list, but the critical score and kernel impact make remediation a priority.
OpenCVE Enrichment
Debian DSA