Impact
A buffer over‑read in the Linux kernel's NFS read past the bounds of a struct sockaddr field and leak unmember. The over‑read can expose memory contents to userspace via NFSD_A_RPC_STATUS_SADDR6/DADDR6 netlink attributes, potentially revealing sensitive data. The flaw arises when an IPv6 client is serviced, causing the code to cast to a larger struct sockaddr_in6 and read beyond its allocated space. This weakness falls under CWE‑125 – Buffer Over‑read.
Affected Systems
The vulnerability is present in the Linux kernel on all versions before the removal of the prototype that declares rq_daddr and rq_saddr as plain struct sockaddr. Exact version ranges are not provided, but all builds that have not applied the patch commit that widens these fields to struct sockaddr_storage are affected.
Risk and Exploitability
The CVSS base score is 6.5, indicating a medium severity that can be leveraged by any unprivileged process running in the same network namespace. The EPSS score is < 1%, and the entry is not listed in the CISA KEV catalog, suggesting no widespread exploitation detected yet. Because the attack path requires no special privileges and relies on standard NFS netlink commands, the risk to untrusted users.
OpenCVE Enrichment
Debian DSA