Impact
An NFS server grants a delegation in an OPEN reply. The client records the delegation through nfs_inode_set_delegation(); however, some error paths exit without sending a DELEGRETURN message. As a result the server remains under the impression that the client still holds the delegation. When the server attempts to recall the delegation, the client, having never recorded the stateid, replies with NFS4ERR_BADHANDLE. The server then revokes the delegation and moves it onto its cl_revoked list, and any subsequent SEQUENCE reply includes SEQ4_STATUS_RECALLABLE_STATE_REVOKED. The client's state manager repeatedly issues TEST_STATEID operations against the revoked delegation, leading to a persistent loop.
Affected Systems
The affected systems are Linux kernel NFS server implementations. No specific kernel versions are provided, so the scope is all kernels that have not yet incorporated the change to correctly send DELEGRETURN on error paths. Administrators should consider all vulnerable NFS deployments at risk until the kernel is updated.
Risk and Exploitability
The CVSS score of 7.5 designates this vulnerability as high severity. The EPSS score of less than 1% indicates a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is an attacker capable of sending NFS requests that trigger the error flows; no other prerequisites are specified. The risk remains moderate, and applying the fix promptly is recommended.
OpenCVE Enrichment