Impact
In the Linux kernel NFS daemon, replay of a seqid operation can drop a reference to a state owner that was never taken, causing a reference count underflow on the stateowner and leaving a leaked state ID reference that can stall concurrent close operations. This flaw is an instance of improper resource management (CWE-825) that can lead to a use‑after‑free scenario within the kernel, potentially corrupting memory or crashing the system.
Affected Systems
The vulnerability resides in the NFSv4 implementation of the Linux kernel and affects all Linux distributions that ship the standard kernel, regardless of vendor. No specific kernel versions are listed in the data, indicating that the issue may exist in multiple recent releases until patched via an update.
Risk and Exploitability
The CVSS score of 9.8 denotes critical severity. The EPSS rank of <1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in CISA KEV. The issue can be triggered by a replayed seqid operation that causes an EAGAIN path dropping an unacquired stateowner reference, leading to a kernel reference count underflow and use‑after‑free, potentially crashing the system. Based on the description, it is inferred that an attacker would need the ability to send or influence NFSv4 requests to a vulnerable server, making the attack vector likely remote NFS traffic. Given the low EPSS and lack of public exploitation, the risk is critical but currently low likelihood.
OpenCVE Enrichment
Debian DSA