Impact
The vulnerability is an out‑of‑bounds read in the Linux kernel’s NFS server implementation. A user with CAP_NET_ADMIN can send a malformed NFSD_A_SOCK_ADDR containing a 16‑byte AF_INET6 structure that is too short for the kernel logic, causing three parsing functions to read 12 bytes beyond the buffer. This read exposes arbitrary kernel memory data, which an attacker could use to assist further exploitation. The flaw is a classic CWE‑125 out‑of‑bounds read.
Affected Systems
The affected systems are all Linux kernel installations before the patch that added proper sockaddr length validation in the NFS listener configuration. The advisory does not list specific kernel release numbers, so any host running a pre‑patch kernel is potentially vulnerable. Only the NFS server component contains the vulnerable code path, so only machines that run the NFS server and have CAP_NET_ADMIN privileges are at risk.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate severity. The EPSS score of less than 1% shows the exploitation probability is very low at the time of assessment. The vulnerability requires local privilege (CAP_NET_ADMIN) and is not remotely exploitable, and it is not registered in the CISA KEV catalog. If exploited successfully, the out‑of‑bounds read could reveal kernel memory contents but does not directly lead to code execution; the attacker would still need additional steps to leverage the disclosed information for further compromise.
OpenCVE Enrichment
Debian DSA