Impact
The vulnerability lies in the Linux kernel’s NFSD_MAY_TRUNC) is performed before the inode lock is taken. This creates a time‑of‑check to time‑of‑use window that can be exploited to truncate a file that is marked append‑only. Based on the description, it is inferred that an attacker could trigger this race by sending a SETATTR request that does not shrink the file and then timing an append operation such that the file size grows before the inode lock is acquired. The result is data loss or corruption of the append‑only file.
Affected Systems
All Linux kernel builds that have not incorporated the NFS server patch are affected, regardless of distribution. The flaw is located in core kernel code that handles NFS set‑attribute requests, so any deployment running an unpatched NFS daemon is at risk. No specific version range is given, implying that the issue exists in every kernel release that lacks the fix.
Risk and Exploitability
The CVSS score of 9.1 indicates high severity, while the EPSS score of less than 1% suggests a low probability The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an NFS client with write access that can issue a SETATTR request while another process performs an append, exploiting the race. Because the window of opportunity is narrow and the attacker requires privileged write access on the NFS server, the overall risk is high impact but low likelihood in environments where the condition is satisfied.
OpenCVE Enrichment
Debian DSA