Vulnary
← back to the feed
Critical· 9.1official fix available

CVE-2022-48829

A bug in the Linux kernel’s NFSv3 server could let a client set a file size larger than the kernel can handle, causing the server to silently truncate the size. This could lead to data loss or corruption.

publishedJul 16, 2024
last modifiedAug 4, 2026
sourcesNVD
severity · cvss
9.1
critical · how bad it is
exploitation · epss
<1%
48th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 4, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

Linux kernel 5.17 and earlier versions that have not applied the NFSv3 SETATTR/CREATE size handling fix. Typical users are system administrators running NFSv3 servers on those kernels.

02

Real-world impact

An attacker could trick the NFS server into storing a file with an incorrect size, potentially causing data corruption or loss. The attacker does not need any special privileges or user interaction.

03

Why this severity

The CVSS score of 9.1 reflects that the vulnerability is exploitable over the network, requires no privileges, and can lead to complete loss of data integrity and availability. The lack of user interaction and the high impact on integrity and availability drive the high score.

04

What to do about it

official fix available
recommended steps
  1. 01Upgrade the Linux kernel to a version that includes the NFSv3 size handling fix (e.g., any release after the patch that fixed CVE-2022-48829).

NVD-referenced vendor advisory

05

Timeline

  1. Jul 16, 2024 · Jul 16, 2024
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Aug 4, 2026 · 2d ago
    Advisory updated
    The NVD record was last revised.
  3. Aug 5, 2026 · 1d ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactNone
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →