An issue was discovered in fs/nfs/dir.c in the Linux kernel before 5.16.5. If an application sets the O_DIRECTORY flag, and tries to open a regular file, nfs_atomic_open() performs a regular lookup. If a regular file is found, ENOTDIR should occur, but the server instead returns uninitialized data in the file descriptor.
https://www.spinics.net/lists/stable/msg531976.html
https://www.debian.org/security/2022/dsa-5096
https://www.debian.org/security/2022/dsa-5092
https://lists.debian.org/debian-lts-announce/2022/03/msg00012.html
https://lists.debian.org/debian-lts-announce/2022/03/msg00011.html