PT-2024-10535 · Linux+3 · Linux Kernel+3

Chuck Lever

·

Published

2022-02-09

·

Updated

2025-06-27

·

CVE-2022-48829

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the NFSD component of the Linux kernel, specifically with the handling of large file sizes in NFSv3 SETATTR/CREATE procedures. The iattr::ia size is a loff t, and the procedures must carefully handle incoming client size values that are larger than s64 max without corrupting the value. Silently capping the value results in storing a different value than the client passed in, which is unexpected behavior. The fix involves removing the min t() check in decode sattr3(). According to RFC 1813, only the WRITE procedure should return NFS3ERR FBIG.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-01086
CVE-2022-48829
OPENSUSE-SU-2024_2947-1
RHSA-2024:5266
RHSA-2024:5281
RHSA-2024:5282
RHSA-2024:6992
SUSE-SU-2024:2892-1
SUSE-SU-2024:2894-1
SUSE-SU-2024:2901-1
SUSE-SU-2024:2902-1
SUSE-SU-2024:2929-1
SUSE-SU-2024:2939-1
SUSE-SU-2024:2940-1
SUSE-SU-2024:2947-1

Affected Products

Astra Linux
Linux Kernel
Red Os
Suse