Impact
A flaw in the NFS server’s handling of the GETDEVICEINFO RPC causes the response payload size to be incorrectly calculated. The server declares does, and this discrepancy results in the client receiving stale contents from previous replies. The data leak occurs for every GETDEVICEINFO reply, potentially exposing residual data from prior operations and causing downstream corruption when subsequent fields are decoded.
Affected Systems
All Linux kernel builds that compile with the NFS server (nfsd) and expose the GETDEVICEINFO operation are vulnerable. Kernel versions that lack the fix for the XDR padding mismatch must be considered exposed until patched.
Risk and Exploitability
The CVSS score of 5.9 categorises the issue as moderate. The EPSS score of less than 1 % indicates that exploitation is unlikely, and the vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is a remote NFS client that sends a crafted GETDEVICEINFO request over the network to the vulnerable server, causing the malformed response to be produced and the client to receive leaked data.
OpenCVE Enrichment