Linux Kernel NFSD Trace Point Crash Vulnerability

Vulnerability

A vulnerability in the Linux kernel's NFS server component (NFSD) has been addressed. When tracing is enabled, a crash occurs in the 'nfsd4_read_release' function due to the 'trace_nfsd_read_done' trace point. This issue was observed during the 'pynfs read.testNoFh' test.

Impact

The vulnerability can lead to a crash of the NFS server process, causing a denial of service by interrupting NFS service availability.

Reproduction

To reproduce this issue, enable tracing in the Linux kernel and run the 'pynfs read.testNoFh' test. The 'trace_nfsd_read_done' trace point will cause a crash in the NFS server.

Remediation

Users can apply the latest patches available in the Linux kernel stable tree to address this vulnerability.

Added: Dec 8, 2025, 1:18 AM
Updated: Dec 8, 2025, 1:18 AM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.7
remediation
7.7
relevance
1.3
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.