Impact
The vulnerability is a use‑after‑free (CWE‑825) in the Linux kernel NFS daemon, triggered by a race between async copy operations and teardown paths. When an async copy structure is freed while its copy thread is still dereferencing it, the kernel may crash or, if an attacker can manipulate the corrupted memory, potentially gain higher privileges on the host.
Affected Systems
Affected version information is not available. The vulnerability resides in the NFS server subsystem of the Linux kernel, so any distribution running an unpatched kernel with the NFS daemon could be at risk until the fix is applied.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. The EPSS score is reported as less than 1%, meaning the probability of exploitation is considered very low. The vulnerability is not listed in the CISA KEV catalogue. The likely attack vector is a remote NFS client that can trigger the async copy race through normal file operations. While exploitation would be complex, the potential impact includes kernel memory corruption, service disruption, and possible privilege escalation.
OpenCVE Enrichment