CVE-2022-48828: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.6% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix ia_size underflow iattr::ia_size is a loff_t, which is a signed 64-bit type. NFSv3 and NFSv4 both define file size as an unsigned 64-bit type. Thus there is a range of valid file size values an NFS client can send that is already larger than Linux can handle. Currently decode_fattr4() dumps a full u64 value into ia_size. If that value happens to be larger than S64_MAX, then ia_size underflows. I'm about to fix up the NFSv3 behavior as well, so let's catch the underflow in the common code path: nfsd_setattr().

Affected products

  • Linux Linux Kernel: before 5.4.295 (fixed in 5.4.295); from 5.5, before 5.10.220 (fixed in 5.10.220); from 5.11, before 5.15.24 (fixed in 5.15.24); from 5.16, before 5.16.10 (fixed in 5.16.10); version 5.17 only

Published 2024-07-16. Last modified 2026-08-04.