Impact
The Linux NFS daemon suffers from an unbounded allocation of symlink target When a client sends a symlink creation request containing path size, the kernel’s nfsd4 target before validating its size, enabling a malicious client to force a kmalloc that can consume several megabytes of kernel memory. This memory can persist until the NFS compound operation completes, potentially exhausting kernel memory and leading to a server crash or CWE-770, indicating resource exhaustion.
Affected Systems
The vulnerability applies to all builds of the Linux kernel that do not include the patch that adds an upper bound check on symlink target lengths. No specific kernel version range is enumerated, so any compile‑time Linux kernel before the commit that implements the check is potentially vulnerable. Systems running an NFSv4 server and exposing the service to untrusted clients should verify whether the affected code path is present in their kernel version.
Risk and Exploitability
The CVSS score of 7.5 and EPSS score of less than 1% indicate a low likelihood of exploitation at present. This vulnerability is not listed in the CISA KEV catalog. The flaw can likely be exploited remotely by sending a specially crafted NFS connectivity to the NFS server. The exploit affects kernel space and can lead to a denial of service against the entire server.
OpenCVE Enrichment
Debian DSA