Impact
This vulnerability targets the NFSD subsystem in the Linux kernel. During an expiration release the nfsd_ssc_lock is dropped and later reacquired to delete an expired entry. Because the walk uses a safe iteration macro that does not retain concurrent thread may free that element while the lock is released. The next iteration then dereferences a freed structure, causing a use‑kernel crash or other undefined memory corruption. No privilege escalation or data exposure is explicitly claimed in the description.
Affected Systems
All Linux kernel builds that include the NFSD module prior to the patch are potentially affected. The CNA data lists the generic Linux kernel CPE without version information, so any kernel version lacking the recent patch falls under risk.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity, and the EPSS score of <1% indicates a very low exploitation probability at the current time. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is likely triggered via NFS client operations that cause a source‑server mount to fail during the lock‑drop window, leading to a race the risk remains contained to environments where an attacker can influence NFS mount activity, potentially causing a kernel crash and denial of service.
OpenCVE Enrichment
Debian DSA