Impact
In the Linux kernel, the NFSv4.1 decoder creates callback reference lists that remain uninitialized when no references are present, later freeing these stale pointers with kfree. The resulting memory corruption can crash the kernel and, on the rare occasion where freed memory is reused, allow execution of arbitrary code in kernel space.
Affected Systems
All Linux kernels that include the NFSv4.1 implementation before the commit that replaces kmalloc_objs with kzalloc_objs, typically mainstream distributions before the referenced patch is applied.
Risk and Exploitability
The EPSS is below 1%, indicating a very low chance of current exploitation, and the vulnerability is not listed in CISA KEV. Nonetheless the CVSS score of 9.8 signals a critical risk. The likely path involves a malicious NFS client sending a crafted request with an empty referring‑call list to a server running the affected kernel, inducing the stale free and subsequent crash or code execution.
OpenCVE Enrichment