Impact
The flaw occurs when the NFS server processes a lookup request that references a directory entry lacking a lookup method. This missing method can trigger a null‑pointer dereference in the nfserr_notdir path, leading the kernel to crash. The weakness identified is a null pointer dereference (CWE‑476). The crash causes a sudden loss of service for any client whose request reaches the vulnerable code path.
Affected Systems
All Linux kernel versions that have not incorporated commit e75b23f9e323 in the NFSD mode‑check logic are affected. This includes the mainline upstream kernel as well as distribution kernels that have not yet applied the patch or an equivalent vendor update. The issue is triggered only when the NFS server exports a filesystem that may be re‑exported, and an NFS client may send a LOOKUP that targets a directory entry without a lookup method.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.2, indicating high severity, but its EPSS score is less than 1 %, reflecting a very low exploitation likelihood in the wild. It is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote via NFS: an attacker only needs the ability to send crafted NFS LOOKUP requests to the affected server. Successful exploitation would cause the kernel to crash, resulting in a denial‑of‑service attack with no direct privilege escalation or data exfiltration potential as per the current data.
OpenCVE Enrichment
Debian DSA