Impact
NFSD cleans up lock owners during an NFS client teardown. A lock owner client is destroyed, the cleanup routine dereferences the owner after the blocked lock is freed, causing a null pointer dereference. This use‑after‑free flaw (CWE‑476) results in a kernel crash and therefore a denial of service on the affected system.
Affected Systems
All Linux kernels that have not yet are affected. The flaw resides in the NFS server module bundled with the kernel, so any distribution running an unpatched kernel that includes the NFSd subsystem is at risk. The specific CPE indicates all Linux kernel releases; individual distribution names are not listed.
Risk and Exploitability
The CVSS base score of 9.8 marks this flaw as critical, and the EPSS score of less than 1 percent suggests that exploitation attempts are currently rare. There are no publicly available exploits. Based on the description, the likely attack vector is an attacker who can trigger an NFS client teardown, such as by disconnecting clients or sending malformed NFS requests. The flaw is not listed in CISA’s KEV catalog, so the severity and potential for a full system crash mean that the risk should not be neglected.
OpenCVE Enrichment
Debian DSA