Impact
A race condition in the Linux kernel’s NFS server code, specifically in the nfsd_copy_file_range function, causes the writeback error cursor to be sampled after a concurrent commit or write operation. This results in the kernel incorrectly reporting a successful copy operation even when a write loss occurs, leading to silent data loss.
Affected Systems
The flaw copy operation without the patch. No specific kernel versions are listed, so all distributions shipping a vulnerable kernel need to be considered.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while the EPSS score of <1% suggests the likelihood of exploitation is low. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a concurrent NFS client initiating copy_file_range on a shared inode while a commit or write occurs, creating the race window needed for the flaw to manifest. Exploitation requires the ability to perform these operations.
OpenCVE Enrichment
Debian DSA