Impact
The vulnerability is a use‑after‑free flaw in the Linux NFS During a DESTROY_SESSION request, the kernel may free a session while an in‑flight rpciod callback still references cl_cb_session. The freed memory can then be dereferenced, leading to kernel memory corruption. This flaw allows arbitrary kernel memory writes, which could be leveraged to execute code, although this outcome is inferred from the nature of the use‑after‑free rather than explicitly documented.
Affected Systems
All Linux kernel releases that ship the NFSv4 server component are affected until a patch that RCU‑protects cl_cb_session is applied. The advisory does not list specific versions, so any kernel lacking the commit that implements the RCU guard is vulnerable. Downstream distributions should upgrade to the latest kernel that includes the fix or disable the NFSv4 server component if an upgrade is not immediately possible.
Risk and Exploitability
The CVSS score of 9.8 indicates a very high severity, while the EPSS score of < 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector, inferred from the description, is a remote NFSv4 client that sends a DESTROY_SESSION request to trigger the race condition. Local or remote exploitation would require the attacker to control or influence the timing of the session teardown, a detail not explicitly verified in the advisory.
OpenCVE Enrichment
Debian DSA