Impact
The Linux kernel contains a flaw in the NFS daemon startup sequence: writing to /proc/fs/nfsd/unlock_filesystem or issuing the NFSD_CMD_UNLOCK_FILESYSTEM or NFSD_CMD_UNLOCK_EXPORT netlink command triggers a walk of the NFSv4 client hash tables to revoke open state and cancel asynchronous copy operations. The handlers incorrectly gate this walk on nn->nfsd_serv, which is initialized before the hash table is allocated. The walk therefore dereferences a NULL pointer in nn->conf_id_hashtbl. A local administrator with CAP_SYS_ADMIN can trigger this path without ever starting the NFS server, resulting in a kernel panic and system crash. The primary impact is a denial of service that can affect all processes running on the host.
Affected Systems
This vulnerability affects all Linux kernel releases that implement the NFS server but have not been patched to introduce the NFSD_NET_UP guard. Distributions that ship the kernel with the NFS daemon (e.g., mainstream distros such as Ubuntu, Debian, Red Hat, SUSE) are potentially affected. No specific version range is provided by the CNA, therefore any unpatched kernel is at risk.
Risk and Exploitability
The CVSS score is not supplied, but the EPSS score is below 1 %, indicating a low exploitation probability at present. The vulnerability is not listed in the CISA KEV catalog, reducing the chance of observed malicious exploitation. Nonetheless, the flaw requires only local privileged access—a common scenario—so any attacker who can obtain CAP_SYS_ADMIN privileges can cause a system‑wide crash. Prompt remediation is advised even though the exploitation likelihood remains low.
OpenCVE Enrichment
Debian DLA
Debian DSA