Impact
The Linux kernel’s NFS daemon contains a race condition that can cause a use‑after‑free during copy‑notify stateid revocation. The flaw arises when a revoke path can drop a reference without unlinking the stateid, allowing a concurrent revoke or expiry to free the record while another kernel path is still reading it. Based on the description, it is inferred that exploitation of the use‑after‑free could lead to local code execution with kernel privileges.
Affected Systems
The vulnerability affects Linux kernel installations that run an NFS server (the nfsd component). All kernel versions that include this module and have not applied the vendor patch are impacted. Systems not running NFS are not influenced.
Risk and Exploitability
The flaw carries a CVSS score of 8.8, indicating high severity. Its EPSS score of < 1 % suggests a very low likelihood of exploitation, and it is not listed in the CISA KEV catalog. The likely attack vector involves a race condition between concurrent revoke or expiry operations and an active user holding a reference to the copy‑notify stateid; based on the description, the exact conditions for triggering this use‑after‑free remain uncertain. Based on the information available, no publicly documented exploit has been reported.
OpenCVE Enrichment
Debian DSA