Impact
The vulnerability is an internal error in the Linux kernel’s NFSv4.2 implementation where the layout statistics encoder reserves only 256 bytes for the payload but may generate larger messages. When a server includes a filehandle close to the maximum size and adds additional latency information, the encoded payload exceeds the reserved buffer. This causes the XDR allocator to return NULL while a lock is held, leaving the synchronization primitive permanently blocked. The result is that subsequent NFS operations that require the lock cannot complete, effectively denying service to all clients that rely on the affected NFS server.
Affected Systems
The flaw appears in all Linux kernel versions prior to the patch that raises PNFS_LAYOUTSTATS_MAXSIZE to 384 bytes. The affected code resides in the mainline kernel source; thus any distribution shipping a kernel with the 256‑byte limit is vulnerable. The threat applies only to systems exposing NFSv4.2 and that allow the layout statistics feature; it does not affect earlier protocol versions or non‑NFS services.
Risk and Exploitability
The CVSS score is 7.5, indicating a high impact vulnerability. The EPSS score of < 1% suggests the likelihood of exploitation is currently low, and the feature is not listed in the CISA KEV catalog. An attacker would need to control a malicious NFS client that requests layout statistics, causing the server’s encoder to exceed the reserved buffer and hold a lock indefinitely. Once the lock is held, the server’s NFS daemon stalls, requiring a reboot or manual intervention to restore service.
OpenCVE Enrichment
Debian DLA
Debian DSA