Impact
The Linux kernel contains a bug in the NFSv4.1 pNFS layout handling routine, pnfs_layout_process. When a new layout stateid is returned while an older valid stateid remains, the code attempts to move invalidated layout segments into a temporary free_me list. However, the failure path that normally drains this list is missing, so the segments stay allocated and continue to grow. The accumulated memory consumption can eventually exhaust kernel memory, destabilize the server, or cause a crash. This is a resource exhaustion flaw (CWE‑772).
Affected Systems
The issue exists in any Linux kernel that compiles an NFSv4.1 server without the commit that restores the pnfs_free_lseg_list drain. Any distribution shipping an older kernel or a custom kernel that has not incorporated that patch is impacted. No specific version numbers are given, so all kernels before the patch are vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1% shows a very low but non‑zero chance of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can trigger the memory leak by sending many layout state transition requests from an untrusted NFS client over the network; local privilege escalation is not required. Based on the description, it is inferred that this can be achieved remotely. Because the flaw can be exercised remotely, the potential impact is higher in exposed NFS servers.
OpenCVE Enrichment
Debian DSA