Impact
The Linux NFS server contains a flaw in the nfsd4_decode_posixacl routine, where a 32‑bit ACL entry count is read from the network and passed directly to the allocation and bubble‑sort functions. Because the count is not limited, a malicious client can supply an arbitrarily large number, forcing the kernel to perform an unbounded O(n²) sort that consumes excessive CPU resources. This vulnerability trigger a denial of service without authentication.
Affected Systems
Affected systems are Linux kernels that expose an NFS server and lack the bounds‑check introduced by commit 5fc51dfc2eb1. Any distribution shipping a kernel revision prior to integrating this commit is potentially vulnerable; kernels that have received the patch are considered safe.
Risk and Exploitability
The CVSS score of 7.5. The EPSS score is below 1%, indicating a low but non‑zero likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. An attacker4 requests to the target server; by crafting a request with a very large ACL count the server will waste CPU cycles performing the bubble sort before rejecting the request with nfserr_inval. No additional privileges or authentication are required.
OpenCVE Enrichment