Impact
The Linux kernel’s NFSv4 server contains a race condition in the handling use‑after‑free flaw identified as CWE‑825. The state is initialized after it IDR and parent list; an OFFLOAD_CANCEL request with a crafted client ID and so_id can arrive while the initialization is still in progress, leading to use‑after‑free that corrupts kernel memory. The description does not describe any additional exploitation steps, so the effect is limited to kernel memory corruption or a crash of the NFS server, potentially causing a denial of service.
Affected Systems
All Linux kernel versions that include the NFSv4 server component and have not yet applied the commit changes are potentially affected. The advisory provides no specific release numbers; the vulnerability exists in the code paths referenced by the commit IDs. Systems running an unpatched kernel with the NFSv4 daemon enabled are at risk.
Risk and Exploitability
The CVSS score of 9.8 classifies the issue as critical severity1 % and the vulnerability is not listed in the CISA KEV catalog, indicating that no publicly known exploits have been observed and the likelihood of exploitation is low. The likely attack vector is an attacker with network access to the NFS service who sends a carefully timed OFFLOAD_CANCEL as inferred from the race condition described. If the race corruption or cause the NFS server to crash, disrupting service availability.
OpenCVE Enrichment
Debian DSA