Impact
A flaw in the Linux kernel’s NFS server allows the function nfsd_file_do_acquire() to operate on a file returned by dentry_create() that might not have actually been opened. This mis‑use of an uninitialized resource (CWE-908) can lead the NFS server to perform unexpected file operations, potentially causing data corruption or unauthorized access to files by clients. The vulnerability does not provide remote code execution but can impact the confidentiality and integrity of data stored on the server.
Affected Systems
The issue affects all Linux kernel builds that include the buggy nfsd implementation and predates the patch that checks the FMODE_OPENED flag. No specific kernel versions are enumerated in the CVE data, so every kernel compiled from the public source before the referenced commit is considered vulnerable.
Risk and Exploitability
With a CVSS score of 7.5 the flaw has high severity, yet the EPSS score of <1% and the fact that the weakness relies on a rarely‑occurring race condition suggest a low to moderate likelihood of exploitation. The attack would require a malicious or compromised NFS client that can request a file in a way that forces nfsd_file_do_acquire() to work with an unopened file. The flaw is not listed in the CISA KEV catalog and is unlikely to be active in production unless the kernel is unpatched and exposed to untrusted network clients.
OpenCVE Enrichment