Impact
In the Linux kernel, the NFS server fails to reset the operand count when releasing compound arguments. If the RPC status counter becomes stuck at an odd value, the status dump handler reads entries beyond the valid array, leaking adjacent slab-bounds read exposes confidential kernel data to userspace. The flaw could result in the unauthorized retrieval of kernel memory contents, potentially revealing sensitive information such as cryptographic keys or configuration data.
Affected Systems
The affected product is the Linux kernel. No specific kernel versions are enumerated in the advisory; the fix is included in commits referenced in the source URLs and applies to all kernel releases containing the nfsd4_release_compoundargs function.
Risk and Exploitability
The CVSS score of 7.1 indicates a High severity. The EPSS score is less than 1% and the vulnerability is not listed in CISA KEV. Consequently, the exploitation likelihood is low, but because the vulnerability requires an error path to be hit and the exposure is via netlink, the overall risk is moderate. The recommended mitigation is to apply a kernel update that includes the opcnt reset change.
OpenCVE Enrichment
Debian DSA