Impact
The Linux kernel contains a use‑after‑free flaw in the NFS server (nfsd) where a freed nfsd_file object can be accessed after an RCU grace period. When a client opens a local file handle, the kernel performs a cmpxchg on the nfsd_file pointer and then increments its reference count without holding an rcu_read_lock. If the object has already been freed and the slab page reclaimed, the refcount bump succeeds on stale memory and the kernel dereferences fields that belong to a reclaimed buffer. This can lead to a kernel crash or, in the best case for the attacker, execution of code with kernel privileges. The severity is high because it is a kernel‑space use‑after‑free that can provide full system compromise.
Affected Systems
Any Linux distribution running an NFS server (nfsd) on a kernel version that has not yet applied the patch fixing the RCU handling bug is affected. The flaw was resolved in the downstream kernel update that followed the public disclosure, but all prior releases remain vulnerable. Vendors include all major Linux distributions that ship the upstream kernel.
Risk and Exploitability
The CVSS score of 7.8 reflects a confluence of high impact and lack of necessity for privileged local access. The EPSS score below 1% indicates that, as of the last update, only a very small fraction of monitored traffic patterns targeted this weakness, but the flaw is still considered exploitable by an attacker with network access to an NFS client interface. The vulnerability is not listed in the CISA KEV catalog, which means no known active exploits have been identified yet. However, the remote attack vector is straightforward: an attacker sends a crafted NFS open request to a server that competes for the same nfsd_file slot, triggering the race that leads to a use‑after‑free. Once triggered, the kernel can crash or yield control to arbitrary code.
OpenCVE Enrichment