Impact
The flaw is a NULL pointer dereference (CWE-476) in the Linux NFS server’s layout state ID allocation code. In nfsd4_alloc_layout_stateid the field fi_deleg_file is read without holding fi_lock when the parent stateid represents a delegation. A concurrent delegation revoke performed by the kernel laundromat can clear fi_deleg_file while under fi_lock, causing nfsd_file_get() to return NULL and triggering a BUG_ON. The BUG_ON on the null pointer dereference crashes the kernel, resulting in a denial of service for the NFS service.
Affected Systems
Linux distributions running a kernel that does not yet contain the commit that locks the fi_deleg_file read and replaces the BUG_ON are vulnerable. The issue is limited to the NFS server component; only servers that enable NFSv4 LAYOUTGET and delegations are affected. No specific kernel release numbers are listed in the advisory, so any kernel version prior to the patch is considered vulnerable.
Risk and Exploitability
The CVSS score of 9.8 marks this as a critical vulnerability, while the EPSS score of <1% indicates a low likelihood of exploitation at the time. The flaw is not listed in CISA’s KEV catalog. The attack vector is client‑reachable: an attacker must have access to two NFS clients – one that holds a delegation and another that opens the same file to force a recall – in order to create the race condition that leads to a kernel crash.
OpenCVE Enrichment
Debian DSA