Impact
A bug in the Linux kernel’s NFSv4 client allocation routine causes the callback identifier data structure (IDR) to be left pointing to a freed client object when later initialization steps fail. Subsequent NFSv4 callbacks that perform a lookup using this stale IDR entry will acquire a reference to the already‑freed client, resulting in a use‑after‑free condition. This can corrupt memory, crash the kernel, or provide an attacker with an execution vector, thereby compromising system integrity and availability.
Affected Systems
All Linux kernel releases that contain the NFSv4 client code, including both mainstream and LTS distributions, are affected. The CVE does not list specific version ranges, so any kernel version prior to the patch that introduces the removal of the callback IDR entry on allocation failure is vulnerable.
Risk and Exploitability
The CVSS score of 9.8 reflects a high severity remote code execution risk. Although the EPSS score is reported as less than 1%, indicating a low probability of widespread exploitation, the lack of a KEV listing does not diminish the need for immediate remediation. The vulnerability is internal to the kernel’s NFSv4 implementation; a direct attack vector would involve triggering an NFSv4 client allocation failure, which could potentially be achieved remotely by a client sending crafted requests or locally by an unprivileged user executing privileged system operations. The attack would require the ability to cause the failure path to be taken, after which the exploitation of the stale IDR entry could lead to arbitrary code execution.
OpenCVE Enrichment
Debian DLA
Debian DSA