Impact
The changed code in the Linux kernel’s NFS server (NFSD) exposes a use‑after‑free flaw in the function that revokes client export states. When an export is revoked, the lock protecting the client structure is released before a reference to the client is safely held; this allows the client object to be freed while the revoke routine still dereferences it. The result is a memory corruption that an attacker could exploit to execute arbitrary code with the kernel's privileges.
Affected Systems
All versions of the Linux kernel that include NFSD, before the application of the patch that introduced the fix. The issue is present in the kernel source for the Linux distribution and is not limited to a specific vendor or distribution version.
Risk and Exploitability
This vulnerability receives a CVSS score of 9.8, indicating critical severity, but its EPSS score is under 1 %, suggesting a low probability of exploitation in current datasets. The flaw is not listed in CISA’s KEV catalog. Attacks would typically require an attacker to trigger an export revocation while clients are connected, which generally demands local or privileged administrative access. The lack of a publicly advertised exploitation vector further reduces immediate risk, but the high impact warrants prompt remediation.
OpenCVE Enrichment