Impact
This vulnerability resides in the FAT filesystem implementation of the Linux kernel. It occurs when the function that rebuilds a parent inode for an NFS export path fails to release the buffer head associated with a directory entry after a successful scan. The missing release can result in a memory or resource leak and could allow a malicious client or local user to exhaust kernel memory, potentially destabilizing the system or causing a denial of service. The weakness is a classic resource management flaw.
Affected Systems
All Linux kernel instances that contain the FAT filesystem code and export NFS mounts with the nostale_ro option are potentially affected. The exact kernel versions are not specified in the advisory, but any kernel before the fix referenced in the provided Git commits is vulnerable.
Risk and Exploitability
The EPSS score of less than 1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The reproduced issue requires interaction with the NFS export mechanism, so the likely attack vector involves a local or possibly remote NFS client that can trigger repeated scans of the directory structure. Given the lack of a direct remote code execution path and the nature of the leak, the potential impact is primarily disruption of kernel memory resources rather than immediate privilege escalation.
OpenCVE Enrichment
Debian DLA
Debian DSA