Impact
A use‑after‑free flaw in the Linux kernel NFS server is triggered by writing to /proc/fs/nfsd/unlock_filesystem after the NFS daemon has stopped. The code path nfsd4_cancel_copy_by_sb() operates without holding the nfsd_mutex and before confirming nn->nfsd_serv, allowing it to dereference memory that has already been freed by nfs4_state_destroy_net(). This results in a slab‑use‑after‑free read that can corrupt kernel memory. A local administrator with CAP_SYS_ADMIN can trigger the flaw by stopping the server and then performing the write, as confirmed by KASAN reporting a slab‑use‑after‑free read.
Affected Systems
This flaw affects all Linux kernel implementations that expose the /proc/fs/nfsd/unlock_filesystem interface. The CPE identifier indicates the Linux kernel family and no specific affected version range is provided, so any kernel release prior to the patch is potentially impacted.
Risk and Exploitability
The CVSS score of 4.1 indicates low severity, and the EPSS score of < 1% reflects an extremely low probability of exploitation. The flaw is not listed in CISA’s KEV catalog. Exploitation requires local administrative privileges, the NFS daemon to be stopped, and the capability to write to /proc/fs/nfsd/unlock_filesystem. Given these strict conditions, the likelihood of real‑world exploitation is low, but the flaw can cause a system crash or memory corruption that damages kernel integrity.
OpenCVE Enrichment