Impact
The Linux kernel SUNRPC module has a race condition in the handling of shared socket callbacks, allowing a stale snapshot of callback pointers to be invoked after the lower‑level socket handlers have been restored. This flaw can lead to execution of unintended kernel code or memory corruption, effectively enabling arbitrary code execution within the kernel.
Affected Systems
The vulnerability affects the Linux kernel in general; no specific version range is listed in the provided data. All systems running a Linux kernel that includes the SUNRPC module without the applied patch are potentially impacted.
Risk and Exploitability
The CVSS score of 9.8 classifies this flaw as critical, and the EPSS score of < 1% suggests a low current exploitation probability. The flaw is not listed in CISA KEV, indicating no confirmed widespread attacks yet. The likely attack vector is local, requiring an attacker with ability to open SUNRPC sockets and trigger the timing conditions that lead to the stale callback invocation. Exploitation would result in privilege escalation or kernel compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA