Impact
The Linux kernel NFS daemon can release a session slot while it is still being used, because the session shrinker checks the target maximum slots but does not verify that the calling slot itself is below the shrink boundary or that it is not marked in use. This flaw, identified as CWE‑825, allows an attacker to trigger a use‑after‑free that corrupts kernel memory by writing to a freed slot later in the request handling path.
Affected Systems
All Linux kernel versions earlier than the patch that includes the nfsd4_sequence and free_session_slots fixes are vulnerable. Servers that expose an NFSv4 service run the specific code path that can be abused. The affected platform is the Linux kernel as indicated by the CPE string.
Risk and Exploitability
The CVSS score of 9.8 indicates Critical severity, but the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, so no known widespread exploitation has been observed. The most probable attack vector is through a malicious NFSv4 client that sends a SEQUENCE request with a slot ID that lies outside the allowed range, forcing the server to free a slot that it still uses and causing kernel memory corruption.
OpenCVE Enrichment