Impact
The vulnerability stems from a missing cleanup path in the Linux kernel’s NFSv4 server initialization. When nfs4_server_common_setup allocates a delegation hash table, it delays assigning the destroy callback until the function completes. If any intermediate check fails, the destroy callback remains null, causing the hash table memory leak 4 KiB of unchanged kernel memory. A client that repeats a failed mount can progressively exhaust all unreclaimable slab memory. In a real‑world scenario against an NFSv3‑only server, the leak can reach several gigabytes per day, potentially exhausting available kernel memory and degrading service reliability.
Affected Systems
All Linux kernels with NFS support are affected before the patch commits linked in the advisory; the fix is included in recent kernel releases. The vulnerability is present in Linux distributions that ship a recent kernel with NFS stack compiled. It is reachable from any userspace NFS client when a mount request fails, such as trying to mount an unexported path or against an NFSv3‑only server.
Risk and Exploitability
The CVSS v3 score of 7.5 indicates high severity, and the EPSS score is < 1%, indicating a very low probability of exploitation. The flaw is not listed in CISA’s KEV catalog. The attack vector is trivially reachable from any NFSv4 mount; a malicious or misconfigured client that repeatedly attempts mounts against an NFSv3‑only server or a nonexistent export exploitation and the potentially catastrophic service degradation, the overall risk is significant.
OpenCVE Enrichment