Impact
A reference to the NFS export (sc_export) is never released when reaping open or lock state identifiers. The reference count is never decremented, which pins the export and blocks its unmount for the entire lifetime of the state identifier. As a result the NFS export cannot be safely removed, leading to a denial‑of‑service condition in which a client or administrator cannot cleanly disconnect the service. The issue is a classic resource‑management flaw that can be triggered by normal NFS state‑id usage.
Affected Systems
The vulnerability exists in the Linux kernel, affecting all kernel versions that include the original NFSv4 state‑id handling code. No specific release is listed, but the flaw applies to any Linux system running NFSd that has not yet incorporated the reference‑count fix. Affected vendors include the upstream Linux distribution maintainers who ship the kernel.
Risk and Exploitability
The specific CVSS score is not provided in the data, and the EPSS score is less than 1%, indicating a very low but non‑zero probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog, and no public exploits are documented. An attacker would need to create or manipulate NFS state identifiers—either through a remote NFS client or by leveraging local privileged access—to keep an export reference pinned and prevent unmount operations. Because the flaw requires the kernel to maintain the state and does not involve arbitrary code execution, the risk is moderate with a low likelihood of exploitation based on the available metrics.
OpenCVE Enrichment