Impact
The flaw resides in the Linux kernel's NFSv4 implementation, specifically in the nfsd component. When a delegation recall fails to enqueue on the callback workqueue, the NFSD4_CALLBACK_RUNNING flag is left set. This flag is never cleared on subsequent attempts to break the same delegation, leading the server to silently skip required recalls. As a result, stale delegations persist, blocking conflicting file opens or locks and effectively denying access to NFS clients. The weakness is a logic error that allows the system stateWE‑911).
Affected Systems
NFSv4 servers running the Linux kernel on any distribution that has not incorporated the commit adding a clear of the CALLBACK_RUNNING flag when the recall queue fails. All kernel versions prior to the patch are affected, regardless of distribution, as the flaw is present in the core kernel code and not mitigated by other components.
Risk and Exploitability
The CVSS base score of 7.5 classifies this vulnerability as high severity. The EPSS score is below 1 % and the vulnerability is not listed in CISA KEV, indicating a low probability of widespread exploitation. Based on the description, it is inferred that the attacker would need remote network access to an NFSv4 server and must provoke a delegation break that fails to enqueue; the subsequent silent skip of recalls can then cause client operations to stall. No public exploits are known, but the flaw can lead to a denial of service for NFS clients once a stale delegation is established.
OpenCVE Enrichment