Impact
The vulnerability is a use‑after‑free flaw in the file cache disposal path of the Linux NFS daemon. When a net namespace teardown frees a structure that is still being processed by another kernel thread, a dangling pointer can be dereferenced, resulting in kernel memory corruption. The weakness is identified as CWE‑825.
Affected Systems
All Linux kernels that run the NFS daemon and are missing the commit that inlines the fcache disposal state into the nfsd_net structure are affected. The vendor is Linux and the product is the Linux kernel. No explicit version range is provided, so any kernel prior to the inclusion of the fix is potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. The EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild. Based on the description, it is inferred that exploitation would require local or privileged access to the host and could result in kernel memory corruption.
OpenCVE Enrichment