Impact
The Linux NFSv4 server suffers from a memory leak triggered by malformed OPEN compound requests that contain POSIX ACL attributes. When the dispatcher bypasses normal opening logic, it fails to free allocated ACL objects, leaving references dangling in the kernel. Over time, repeated exploitation accumulates unreleased memory, potentially exhausting the kernel heap and destabilizing the NFS daemon. This flaw is a classic example of CWE‑911 (Improper Release of Resources), where resources are not properly freed during error paths.
Affected Systems
Linux kernel, all versions prior to the patch that introduced nfsd4_open_release and updated the op_release handling. Any deployment of the kernel running an NFSd service exposed to NFSv4 clients falls under this category.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, but the EPSS score of <1% suggests that real-world exploitation is rare as of this analysis. The vulnerability is not listed in the CISA KEV catalog. Attackers can trigger the leak by sending crafted NFSv4 compound operations containing malformed OPEN requests with POSIX ACL createhow4 attributes over the network. The impact remains a denial of service via kernel memory exhaustion; the flaw does not provide privilege escalation or data disclosure. The risk is low until an exploit is demonstrated but patching completely mitigates the issue.
OpenCVE Enrichment