Impact
The flaw is a race condition in the Linux NFS server (nfsd) that occurs during the initialization of client notification state. An uninitialized OFFLOAD_CANCEL request from an NFSv4.2 client can cause the kernel to attempt a list_del on a zeroed list_head, producing an oops and crashing the NFS daemon. The resulting kernel panic shuts down the NFS service, exposing all clients to a denial of service. This weakness maps to list handling race conditions (CWE-824).
Affected Systems
The vulnerability affects any Linux kernel that contains the nfs4_init_cp_state path without the latest patch. All distributions running an unpatched kernel are potentially impacted. The fix was introduced in the recent kernel series, so versions prior to that commit remain vulnerable.
Risk and Exploitability
The CVSS score of 7.5 signals high severity, while the EPSS score of less than 1 % indicates a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. An attacker would need access to the NFS service and the ability to issue an OFFLOAD_CANCEL request as an NFSv4.2 client to trigger the race and cause a crash.
OpenCVE Enrichment
Debian DSA