Impact
nfsd4_drop_revoked_stid processes FREE_STATEID for admin‑revoked delegations but fails to set the SC_STATUS_FREED flag before releasing cl_lock. Without this flag, the freed delegation is readded to the revoked list, causing a use‑after cleanup. The flaw can crash the kernel and deny service to NFS clients.
Affected Systems
All Linux kernel releases that have not incorporated commit 1e479576 are vulnerable. The affected products are all distributions that ship the legacy Linux kernel without the SC_STATUS_FREED fix under the vendor identifier Linux:Linux.
Risk and Exploitability
The CVSS score of 9.8 classifies this vulnerability as critical severity. The EPSS score of < 1% indicates a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is network‑based: an attacker would need an NFSv4 client capable of sending a FREE_STATEID request for an admin‑revoked delegation to the vulnerable NFS server. Because control is limited to a specific NFS protocol operation, remote code execution is not possible; the primary impact is a kernel crash leading to denial of service.
OpenCVE Enrichment
Debian DSA