Impact
This vulnerability arises from a use‑after‑free condition in the NFS server component of the Linux kernel. When a client is closed, the kernel retains a state identifier that keeps a dangling pointer to the NFS client object. The cleanup routine then dereferences this pointer while the client may already have been freed by a concurrent expiration path, leading to memory corruption. The severity is high, as a malicious actor can potentially execute arbitrary code with kernel privileges or, at a minimum, crash the kernel.
Affected Systems
All Linux kernel installations that employ the NFS server are potentially affected. The CVE data does not specify exact kernel versions, so users should consider any kernel that may run NFSD vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 9.8 indicates a severe risk. Although the EPSS score is less than 1%, meaning exploitation is currently unlikely, the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, via network access to an exposed NFS server, and the absence of a defensive workaround means a kernel upgrade is required for protection.
OpenCVE Enrichment
Debian DLA
Debian DSA