Impact
The flaw arises in the NFSv4 server’s file creation logic when a filehandle is composed with a directory entry that does not match the intended target. The bug can cause a dentry that is still referenced to be freed and later dereferenced, leading to memory corruption in kernel space. This corruption could crash the kernel or be exploited to gain elevated privileges. It is an improper reference handling weakness, identified as CWE-825.
Affected Systems
Linux systems with kernels that implement the NFSv4 server prior to the recent fixes are affected. The issue applies to all distributions and kernel versions that have not yet incorporated the commit that relocates the fh_compose call. Any system exposing or using the NFSv4 protocol is therefore at risk.
Risk and Exploitability
The CVSS score of 9.8 indicates a high severity flaw. The EPSS score of less than 1% suggests that no widespread exploitation is currently observed. It is not listed in CISA’s KEV catalog. The likely attack vector is remote over the NFSv4 protocol, though local privilege escalation cannot be excluded. An attacker would need to craft an NFSv4 CREATE request that triggers the faulty dentry handling. No public exploits have been disclosed.
OpenCVE Enrichment