CVE Database
/

CVE-2022-48829

Back to search

CVE-2022-48829

Published: Jul 16, 2024

Modified: May 12, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix NFSv3 SETATTR/CREATE's handling of large file sizes iattr::ia_size is a loff_t, so these NFSv3 procedures must be careful to deal with incoming client size values that are larger than s64_max without corrupting the value. Silently capping the value results in storing a different value than the client passed in which is unexpected behavior, so remove the min_t() check in decode_sattr3(). Note that RFC 1813 permits only the WRITE procedure to return NFS3ERR_FBIG. We believe that NFSv3 reference implementations also return NFS3ERR_FBIG when ia_size is too large.

VendorProductVersions

Linux

Linux

affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - < 72c14aed6838b5d90b4dd926b6a339b34bb02e08
affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - < a231ae6bb50e7c0a9e9efd7b0d10687f1d71b3a3
affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - < 37f2d2cd8eadddbbd9c7bda327a9393399b2f89b
affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - < aa9051ddb4b378bd22e72a67bc77b9fc1482c5f0
affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - < a648fdeb7c0e17177a2280344d015dba3fbe3314

Linux

Linux

affected
2.6.12
unaffected
0 - < 2.6.12
unaffected
5.4.295 - <= 5.4.*
unaffected
5.10.220 - <= 5.10.*
unaffected
5.15.24 - <= 5.15.*

+2 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now