Impact
The vulnerability is a missing reference release in the Linux kernel’s NFS server code, representing a CWE‑911: Improper Release of a Resource after Effective Lifetime. The bug causes mntget() and dget() references to remain unreleased when follow_down() fails. As a result, mnt_count and d_count continue to increase for each failed cross‑mount, pinning dentries and blocking unmounts, which can lead to denial of service.
Affected Systems
The vulnerability affects all Linux kernel versions that include the buggy nfsd_cross_mnt implementation without the in the core kernel source, every distribution running a kernel compiled before the commit that introduces path_put(&path) before the error return is vulnerable. Any authenticated NFS client can trigger the flaw via nfsd_lookup_dentry or the NFSv4 READDIR encode path.
Risk and Exploitability
The risk is moderate to high, as the flaw can lead to resource exhaustion and denial of service by preventing successful unmounts. The CVSS score of 7.5 reflects this high severity. The EPSS score is below not listed in the CISA KEV catalog, indicating a comparatively low likelihood of widespread exploitation. Nevertheless, an authenticated NFS client can trigger the flaw by making a request that causes follow_down to fail, for example through nfsd_lookup_dentry or an NFSv4 READDIR encode path. Such an attacker can repeatedly invoke the error path, each time leaking mntget() and dget() references, inflating mnt_count and d_count until the system becomes unable to unmount filesystems or shrink dentries, resulting in a denial of service. This attack vector requires network access to the NFS server and valid client credentials.
OpenCVE Enrichment
Debian DSA