Impact
A NULL pointer dereference occurs in the Linux NFSv4 server (nfsd) when a client carefully crafts a COMPOUND request that creates a foreign filehandle with NULL references and then performs a non‑SAVEFH operation such as SETATTR. The kernel does not verify the filehandle before dereferencing it, causing the nfsd kernel thread to crash and potentially leading to a system reboot. This issue is a classic CWE‑476 NULL Pointer Dereference triggered by insufficient input validation.
Affected Systems
All Linux kernel builds that enable CONFIG_NFSD_V4_2_INTER_SSC are impacted. The advisory does not specify a particular release, so any distribution kernel that includes this configuration without the applied fix is vulnerable. The vulnerability resides in the NFSv4 server (nfsd) module of the Linux kernel.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity surface; the EPSS score is < 1%, reflecting a very low yet non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker who can construct a remote COMPOUND request that includes an inter‑SSC COPY followed by a non‑SAVEFH operation can trigger a null‑pointer dereference in the nfsd kernel thread, leading to a crash of the NFS service and a potential denial of service to users relying on NFS.
OpenCVE Enrichment
Debian DSA