Impact
The vulnerability resides in the NFS daemon’s handling of file cache cleanup. When a cached NFS file is removed by the shrinker, garbage‑collector worker, or fsnotify callbacks, the file can be unhashed from the reference map and then deferred to a per‑network disposal list. If the net‑shut‑down routine runs concurrently, it may miss the unhashed entry and drain the disposal list before the file has been queued, leaving the file and its associated kernel state stranded. The leaked objects accumulate in memory, potentially exhausting resources and degrading system availability. The weakness is identified as CWE‑772, an unreleased resource cycle.
Affected Systems
The Linux kernel’s NFS daemon component is affected. Any kernel build that does not include the documented fix is vulnerable. No specific version ranges are listed, so all current distribution kernels may need verification.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity. The EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV catalog, suggesting a very low likelihood of exploitation in the wild. This is a kernel‑level flaw that requires either local or privileged access to the NFS daemon; the likely attack vector is local exploitation or compromise of a privileged process. An attacker who can trigger the race condition could cause uncontrolled memory growth and eventual service disruption.
OpenCVE Enrichment
Debian DSA