Impact
The flaw is in the NFS server’s state revocation logic. When an administrator triggers a revocation, the code releases a lock before the client structure is fully pinned. A state identifier holds only a bare pointer to the client, so if the client is freed first the kernel dereferences dangling memory, resulting in a use‑after‑free condition (CWE‑825). An attacker who can cause or influence such a revocation can execute arbitrary code in kernel mode or crash the system.
Affected Systems
All Linux kernel releases that do not yet contain the patch series referenced in the advisory are vulnerable. The affected code resides in the common NFS server subsystem, so the flaw applies across all supported distributions and kernel versions prior to the commit that removes the race condition.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical risk for privilege escalation or denial of service. The EPSS score of <1% shows that, as of this analysis, exploitation is considered unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog. Because the description does not explicitly state the attack vector, it is inferred that the exploit requires local or privileged context capable of initiating an admin state revocation; thus the likely attack vector is local with elevated privileges.
OpenCVE Enrichment
Debian DSA