Linux Kernel NFSv4 Use-After-Free Vulnerability

Vulnerability

A use-after-free vulnerability has been identified in the Linux kernel's NFSv4/pNFS implementation. When an open RPC call is canceled, the corresponding open slot and layoutget operation arguments should not be freed, as they may still be in use by the pending RPC call.

Impact

Exploitation of this vulnerability could lead to a use-after-free condition, potentially allowing for memory corruption or arbitrary code execution.

Added: Jun 18, 2025, 6:17 PM
Updated: Jun 18, 2025, 6:17 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.3
remediation
0.0
relevance
0.2
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.