Impact
A flaw in the Linux kernel NFSd tracepoint code wrongly sizes the buffer used for the server sockaddr remote length, leading to an out‑of‑bounds write. The overflow can corrupt kernel memory and expose previously recorded trace data, providing an information‑disclosure vector and, due to execution in kernel context, a potential path to arbitrary code execution. The weakness is classified as CWE‑787.
Affected Systems
The vulnerability affects Linux kernel builds that run an NFS server and accept NFSv2 or NFSv3 requests over UDP. Any kernel containing the unpatched nfsd_fh_verify_err tracepoint is vulnerable. Users should verify that their kernel includes the patch that sizes the server slot with the fix to be immune.
Risk and Exploitability
The CVSS score of 9.8 and the EPSS score of <1% and absence from the CISA KEV catalog indicate no known public exploits. The overrun is reachable by a remote could lead to privilege and high impact warrants urgent action.
OpenCVE Enrichment
Debian DSA