Impact
A race condition between nfs_uuid_add_file() and nfs_uuid_put() in the Linux kernel NFS local‑I/O subsystem can leak reference counts for nfsd_file objects and network namespace references. The leaked references prevent proper teardown of the NFS daemon and its namespace, causing kernel resource exhaustion and a denial of service for the NFS service.
Affected Systems
The flaw affects the Linux kernel, specifically the NFS local‑I/O implementation. Any kernel that contains the vulnerable code path may be impacted. Administrators should verify whether their running kernel includes the nfs_uuid_add_file() logic and apply updates accordingly.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of public exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation would require local interaction with the kernel, typically through privileged processes or repeated NFS operations that trigger the race. An attacker could repeatedly cause failures to accumulate leaked references, eventually exhausting kernel resources and causing the NFS daemon to fail.
OpenCVE Enrichment