Impact
A use‑after‑free flaw is present in the Linux kernel’s NFS daemon when a delegation is revoked. The flaw allows an attacker to create a timing window where the delegation is removed from internal tracking while the client’s memory is freed, causing the daemon to dereference a freed memory block. The resulting kernel memory corruption can crash the NFS daemon or potentially allow an attacker to execute code in kernel context. This is a classic use‑after‑free vulnerability (CWE‑825), and based on the description, the likely attack vector is remote network access to an NFS client that can manipulate delegation timing.
Affected Systems
The affected component is the NFS server (nfsd) in the Linux kernel. All Linux kernel builds that do not include the recent patch fixing the delegation revoke code are vulnerable. The exact version range is not specified, so the commit adding the hardening is at risk.
Risk and Exploitability
With a CVSS score of 9.8, the vulnerability is considered critical. The EPSS score of < 1 % indicates a very low but non‑zero exploitation probability. Based on the description, the likely attack vector would involve remote network access to an NFS client capable of timing a delegation revoke, which could lead to denial of service or, if code execution is achieved, kernel‑level privilege escalation.
OpenCVE Enrichment
Debian DSA