Impact
The Linux kernel NFS daemon contains a logic error in nfsd_direct_write where the loop that processes NFS write segments fails to properly detect partial writes that complete between 50% and 99%. The loop compares the bytes written against a residual count that has already been reduced, causing the condition to trigger only when less than half of the segment is written. As a result, subsequent segments are written at a file offset that is off by the short write amount, overwriting or corrupting data. The vulnerability manifests only when a malicious NFS client issues specially crafted write requests that advance the offset incorrectly. Based on the description, it is inferred that an attacker needs the ability to send NFS write requests to the server and must have write access to a file exposed via NFS, but no higher privileges.
Affected Systems
All Linux kernels that contain the unpatched nfsd_direct_write path are vulnerable, regardless of distribution. The advisory does not enumerate specific kernel releases, so any kernel snapshot prior to the commit appears in the Linux kernel repository should be considered at risk. This includes stock kernels shipped in many popular Linux distributions as well as custom kernels that have not been updated.
Risk and Exploitability
The CVSS score of 7.5 reflects high severity, whereas the EPSS score of less than 1% indicates a low probability of widespread exploitation at this time. The vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector involves remote NFS write access, because the bug manifests when an NFS client sends write traffic that triggers the logic error. Inference from the description suggests that the attacker would need to have write access to an NFS‑exported file, but no other privileged context beyond NFS write access. If the logic error is triggered, file contents can be corrupted or overwritten, potentially leading to data loss or integrity violations.
OpenCVE Enrichment