Impact
A null pointer dereference flaw exists in the Linux kernel’s NFSv4 server code. When a SETATTR request includes delegation timestamp attributes and the client supplies an all‑0xFF stateid, the kernel fails to check for a NULL pointer before accessing it, causing a kernel oops that crashes the system and leads to denial of service. The flaw is classified as CWE‑476 and carries a CVSS score of 7.5, reflecting a high severity impact on availability with no direct effect on confidentiality. Operators should verify their kernel version against the patch that introduces the null‑check guard.
Affected Systems
The vulnerability impacts the Linux kernel’s NFSv4 server component across all Linux distributions that ship this module. Systems running kernel versions that do not include the patch adding the null‑check in nfsd4_setattr are vulnerable. The fix appears in the commits c5119b799a7f57..., c896db123892256..., fe456c8c0931bb3e8a03d429920e87fd85747fba. No specific distribution or version range was enumerated in the CVE, so any publicly available kernel without this patch remains at risk.
Risk and Exploitability
The flaw can be triggered remotely by any NFSv4 client through a COMPOUND transaction that includes the delegation timestamp attributes with the all‑0xFF stateid, requiring no special authentication or privileged state. The EPSS score of <1% indicates a very low exploitation probability today, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread active exploitation. Nevertheless, the CVSS score of 7.5 and the trivial remote trigger path warrant prompt attention, especially for systems exposing NFSv4 to untrusted networks.
OpenCVE Enrichment