Impact
The Linux kernel’s NFS daemon initialization sequence had a flaw that caused debugfs entries to be created before the allocation of necessary slab caches. When the slab allocation failed, the early return from init_nfsd() skipped cleanup, leaving orphaned debugfs files that referenced function pointers in freed kernel text. Subsequent interaction with these stale pointers can trigger a kernel panic, resulting in a local denial‑of‑service.
Affected Systems
All Linux kernel builds that ship the stock NFS server and have not merged the commit which moves nfsd are vulnerable. The affected product is effectively the Linux kernel as a whole; specific version bounds are not listed, so any distribution kernel that predates the patch should be considered at risk.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability that can lead to a kernel crash. The EPSS score is less than 1% and the vulnerability is not listed in CISA’s KEV catalog, suggesting it is not widely exploited. The flaw causes orphaned debugfs files with stale function pointers when slab allocation fails during NFS trigger a kernel panic, though the required platform state or permissions to trigger the crash are not explicitly documented in the CVE description. Prompt patching or containment of debugfs access mitigates the potential impact.
OpenCVE Enrichment