Impact
The Linux kernel contains a NULL pointer dere the nlmsvc_ops structure used by the NFS and lockd subsystems. The structure is published and cleared with plain memory stores, while lockd dereferences it without proper synchronization. When the nfsd module is unloaded while services are running, a stale load can trigger a kernel panic or module‑text use‑after‑free, abruptly terminating all NFS activities. The weakness is cataloged as CWE‑476.
Affected Systems
Any Linux system running a kernel that implements the NFS server and lockd components is affected. The vulnerability is present in mainline kernels before the commits that added RCU protection, and in custom or unpatched distributions that expose the nfsd_lockd_init() and nfsd_lockd_shutdown() functions.
Risk and Exploitability
The CVSS score of. The EPSS score is below 1 %, indicating current exploitation probability is low, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the local unloading or reloading of the nfsd module while the NFS or lockd service is running. A successful exploitation results in a kernel panic, causing a system restart or service outage, thus providing a catastrophic denial of service for all workloads relying on NFS.
OpenCVE Enrichment