CVE-2022-48829
A bug in the Linux kernel’s NFSv3 server could let a client set a file size larger than the kernel can handle, causing the server to silently truncate the size. This could lead to data loss or corruption.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel 5.17 and earlier versions that have not applied the NFSv3 SETATTR/CREATE size handling fix. Typical users are system administrators running NFSv3 servers on those kernels.
Real-world impact
An attacker could trick the NFS server into storing a file with an incorrect size, potentially causing data corruption or loss. The attacker does not need any special privileges or user interaction.
Why this severity
The CVSS score of 9.1 reflects that the vulnerability is exploitable over the network, requires no privileges, and can lead to complete loss of data integrity and availability. The lack of user interaction and the high impact on integrity and availability drive the high score.
What to do about it
- 01Upgrade the Linux kernel to a version that includes the NFSv3 size handling fix (e.g., any release after the patch that fixed CVE-2022-48829).
NVD-referenced vendor advisory
Timeline
- Jul 16, 2024 · Jul 16, 2024PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 5, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- git.kernel.org/stable/c/37f2d2cd8eadddbbd9…patch
- git.kernel.org/stable/c/72c14aed6838b5d90b…patch
- git.kernel.org/stable/c/a231ae6bb50e7c0a9e…patch
- git.kernel.org/stable/c/a648fdeb7c0e17177a…patch
- git.kernel.org/stable/c/aa9051ddb4b378bd22…patch
- cert-portal.siemens.com/productcert/html/ssa-265688…
- cert-portal.siemens.com/productcert/html/ssa-355557…