Impact
The Linux kernel’s NFSv4 NFS server contains a netlink command that holds an RCU read lock and reads operation numbers from a vmalloc buffer. The buffer is freed synchronously with vfree at the end of each compound operation, but the free is not deferred across the RCU grace period. If a compound operation completes while the netlink dump is still reading the buffer, the buffer may be freed and an attacker can read from freed memory, resulting in a use‑after‑free (CWE‑825) that corrupts kernel memory.
Affected Systems
Any Linux kernel that has not implemented the commit that replaces vfree(args->ops in nfsd4_release_compoundargs is potentially affected. The advisory does not specify a version range, so all kernels lacking this commit, regardless of release, are at risk.
Risk and Exploitability
The CVSS score of 7.8 signals high severity, while the EPSS score of <1% indicates a low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the rpc_status netlink interface to be reachable and an NFSv4 service to be running. The or higher privilege is required; therefore the required privilege level is unknown.
OpenCVE Enrichment
Debian DSA