Impact
The vulnerability lies in the NFSv4/pnfs implementation of the Linux kernel. When a data server cache is keyed solely on the multipath address set, devices that share that address but use different NFS protocol versions can map to the same cache entry. A client that first connects with, for example, NFSv3 pins the cache to that version, while a later client connecting with NFSv4 receives a cache referencing a server that does not speak its protocol, causing rpc_call_ops to be invoked for the wrong NFS version. This mismatch leads to a dereference of a NULL pointer during sequence‑slot handling, causing an immediate kernel crash.
Affected Systems
Affected systems are all installations of the Linux kernel that include the NFSv4/pnfs module and use multipath data server caching. The issue has no explicit version bounds in the advisory, indicating that it could impact any kernel revision prior to the fix. Kernel commits that address the flaw are present in the repository references provided, so any system running a kernel older than those commits is potentially vulnerable.
Risk and Exploitability
Based on the description, it is inferred that the attack vector is an NFS client connection to a server that uses multiple data servers with different protocol versions. The EPSS score is less than 1 percent and the vulnerability is not listed in CISA's KEV catalog, indicating a low likelihood of exploitation in the wild. The CVSS score of 7.5 indicates high severity. Because the flaw is triggered by a straightforward NFS client connection, a remote attacker who can inject traffic to an NFS server can cause a denial‑of‑service. Updating the kernel to incorporate the fix removes the vulnerability entirely.
OpenCVE Enrichment
Debian DLA
Debian DSA