Impact
The Linux kernel’s NFS server contains an error in the XDR length calculation performed by nfsd4_ff_encode_layoutget. The improperly accounting for padding and variable‑length fields results in an out‑of‑bounds write or leakage of uninitialized kernel memory to a client. This creates a buffer‑overflow vulnerability (CWE‑805) that can enable an attacker to obtain remote code execution or elevate privileges if the attacker can craft a malicious layout‑get request.
Affected Systems
Vulnerable kernels are those that have not incorporated commit 0380129b1373c437eb35401a174671c8888f4b80. The issue resides in the generic NFS server component across all Linux kernel versions until the patch is applied. Systems running any distribution whose kernel package lacks this update, regardless of major release, are affected.
Risk and Exploitability
The CVSS score of 9.8 reflects critical severity, while the EPSS score of < 1 % indicates a very low probability of exploitation. It is not listed in the CISA KEV catalog. The likely attack vector is remote over a network, requiring an attacker to send a crafted NFSv4 layout‑get request to the vulnerable server. Based on the description, the exploit would involve inducing an out‑of‑bounds write or leaking kernel data to a client; attackers would need network access to the NFS server.
OpenCVE Enrichment
Debian DSA