Impact
The Linux NFS server contains a race condition in the request dispatch routine. The routine sets a status counter to an odd value when a request is decoded, an even value. Paths that drop or encode‑error return with the counter still odd. The lockless reader used for dumpit dumps assumes the counter value indicates stable request arguments; when it remains odd, the reader misses concurrent mutations. This allows the reader to access fields that are still being modified, including the inline operations array, and read past the end of the eight‑element array. The read reveals kernel memory contents and therefore constitutes a possible information disclosure.
Affected Systems
All Linux kernel builds that include the NFS server component and have not yet incorporated the commit restoring the counter on every exit path are affected. The vulnerability exists to the change, regardless of specific release versions.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score of less than 1 % suggests the likelihood of exploitation is low at present, and the vulnerability is not listed in the CISA KEV catalog. The attack requires an NFS client that interacts with the server while the lockless memory information. No public exploitation code exists, but the potential for data exposure justifies prompt remediation.
OpenCVE Enrichment