Impact
In the Linux kernel NFS server, the flaw is introduced when fh_verify() is called early in the setattr path, causing the subsequent fh_want_write() check to be skipped. This omission means that notify_change() can execute without, an NFS client can issue a SETATTR request that modifies file permissions, ownership, or timestamps on exported files without needing the usual write permissions. This ability permits unauthorized attribute modification and can lead to privilege escalation or data tampering.
Affected Systems
The vulnerability impacts the Linux kernel's NFS kernel itself. No specific kernel version is enumerated in the data, implying that any kernel release lacking the fh_want_write() addition is potentially vulnerable. Until the patch is incorporated, all unpatched kernel builds that implement the NFS server should be considered at risk.
Risk and Exploitability
The CVSS score of 9.1 signals high severity, yet the EPSS score of < 1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker can exploit the flaw remotely by sending a malicious SETATTR RPC to a vulnerable NFS server. The attack requires network connectivity and sufficient access to the exported file system; local exploitation would need equivalent privileges. No additional constraints or software dependencies are noted, implying a standard NFS client is sufficient to perform the attack.
OpenCVE Enrichment
Debian DSA