CVE-2022-48828
A vulnerability in the Linux kernel's Network File System (NFS) allows for a data mismatch when handling file sizes. Specifically, certain file sizes sent by an NFS client can cause an integer underflow error within the kernel.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users running Linux kernel version 5.17 or other affected versions that utilize the Network File System (NFS) protocol.
Real-world impact
An attacker could potentially exploit this error to cause system instability or unexpected behavior by sending specially crafted file size values that the kernel cannot correctly process.
Why this severity
The critical score is due to the vulnerability being remotely exploitable over a network without requiring user interaction or special privileges, potentially impacting the integrity and availability of the system.
What to do about it
- 01Update the Linux kernel to a version that includes the fix for the NFSD ia_size underflow.
NVD-referenced vendor advisory
Timeline
- Jul 16, 2024 · Jul 16, 2024PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 5, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- git.kernel.org/stable/c/38d02ba22e43b6fc7d…patch
- git.kernel.org/stable/c/8e0ecaf7a7e57b3028…patch
- git.kernel.org/stable/c/d2211e6e34d0755f35…patch
- git.kernel.org/stable/c/da22ca1ad548429d78…patch
- git.kernel.org/stable/c/e6faac3f58c7c4176b…patch
- cert-portal.siemens.com/productcert/html/ssa-265688…
- cert-portal.siemens.com/productcert/html/ssa-355557…