Impact
The NFS daemon contains a function that checks whether a client has finished reclaiming previous resources. That function builds a deadline from the system clock based on the real‑time clock but compares it to the boot‑time clock. Because the two clocks are measured on different origins, the comparison is always false, so a client can keep the server in a grace period forever. The attacker can trigger this by sending CLAIM_PREVIOUS OPEN requests. As a result all non‑reclaim operations for every client are blocked and the NFS service effectively stops responding, creating a denial of service. The flaw is a classic clock domain mismatch (CWE‑1025).
Affected Systems
The vulnerability exists in the Linux kernel itself, and therefore applies to any Linux distribution that runs the NFS server built into the kernel. No specific kernel version is identified, so all releases with the clients_still_reclaiming function that have not applied the committed patch are potentially impacted.
Risk and Exploitability
The CVSS vulnerability as high severity. The EPSS score is below 1 %, indicating that exploitation is unlikely but not impossible. The flaw is not listed in the CISA KEV catalog. Exploitation required only network access to the NFS interface; no special authentication or elevated privileges are needed. A remote host on the NFS network can send CLAIM_PREVIOUS OPEN requests and trigger the denial of service.
OpenCVE Enrichment
Debian DSA