Impact
The bug occurs when the NFSv4 add‑lease function races with a delegation return, causing nfs4_delete_lease to be invoked with a NULL privilege pointer. This incorrect argument leads to a null pointer dereference inside generic_setlease, which can trigger a kernel panic and result in a denial‑of‑service situation. The primary impact is a crash of the kernel that brings down the affected system. Based on the description, the race condition requires NFS traffic that an attacker can control, so the likely attack vector involves precise timing of NFS operations to trigger the race.
Affected Systems
All Linux kernels that include NFSv4 support and that have not yet applied the fix are vulnerable. This includes any distribution using the upstream Linux kernel before the commit documented in the provided patch links. The affected product family is Linux:Linux, as indicated by the vendor list and the CPE string.
Risk and Exploitability
The EPSS score is reported as less than 1% and the vulnerability is not listed in the CISA KEV catalogue, indicating a low likelihood of exploitation in the wild. Nevertheless, the race condition required for exploitation involves precise timing of NFS operations, increasing attack complexity. If an attacker succeeds, the outcome is a kernel panic that terminates services and causes a denial‑of‑service. Administrators should therefore patch promptly while monitoring NFS activity.
OpenCVE Enrichment
Debian DLA
Debian DSA