Impact
The vulnerability arises when an asynchronous COPY operation in the NFSv4 server leaves a stale IDR entry pointing to a per‑request buffer that is subsequently reused. An IDR traversal that dereferences this dangling entry triggers kernel memory reclamation code to act on garbage, causing a kernel panic. This results in a denial of service. The weakness is classified as CWE-825, improper removal and deallocation of a resource. The CVSS score of 9.8 indicates a critical risk, and although the high.
Affected Systems
All Linux kernel builds that include the NFSv4 server with the async COPY feature enabled are vulnerable. The affected product is the Linux kernel. No precise version range is supplied by the CNA.
Risk and Exploitability
The likely attack vector involves an NFSv4 client issuing a manipulated asynchronous COPY request. Any remote NFS client can trigger the flaw, categorizing this vulnerability as critical. The EPSS score is below 1%, suggesting a very low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Consequently, the risk is moderate due to low exploitation likelihood, but if exploited it would cause a system crash.
OpenCVE Enrichment
Debian DSA