Impact
In the Linux kernel NFS daemon, the OFFLOAD_CANCEL routine can free a copy‑notify state without verifying that the requesting client owns the state. This allows an authenticated NFSv4.2 client to cancel another client’s state, causing loss of that client’s transaction state and potential data loss or service disruption. The flaw is an authorization weakness classified as CWE-639.
Affected Systems
All Linux kernel releases that have not yet implemented the ownership check in the nfsd module are vulnerable. Any distribution hosting an NFSv4.2 server on such a kernel is affected, regardless of specific vendor or patch level.
Risk and Exploitability
The vulnerability has a CVSS score of 5.3, indicating medium severity, while the EPSS probability is less than 1 %, showing low current exploitation likelihood. It is not listed in CISA’s KEV catalog. Attackers must authenticate to the NFS server via NFSv4.2 and send OFFLOAD_CANCEL commands, so the vector is the NFS protocol over the network; exposure to untrusted networks increases risk.
OpenCVE Enrichment
Debian DSA