Impact
The flaw causes the NFS daemon to ignore a failed writeback during an asynchronous COPY operation. The verifier used by the server is not rotated when the copy fails, so the client receives a stable‑verifier value and may believe the data is durable after a COMMIT. This violates the NFS durability contract, allowing a client to assume data has been written correctly when it has not, resulting in data loss.
Affected Systems
The vulnerability is present in the Linux versions that contain the unpatched N range is listed, so any kernel lacking the recent patch that restores write‑verifier rotation is susceptible.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. The EPSS score is less than 1%, showing a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers would need remote network access to send NFS requests to the vulnerable server. The impact is limited to data integrity rather than code execution or disclosure.
OpenCVE Enrichment
Debian DSA