CVE-2022-48829

In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix NFSv3 SETATTR/CREATE's handling of large file sizes iattr::ia_size is a loff_t, so these NFSv3 procedures must be careful to deal with incoming client size values that are larger than s64_max without corrupting the value. Silently capping the value results in storing a different value than the client passed in which is unexpected behavior, so remove the min_t() check in decode_sattr3(). Note that RFC 1813 permits only the WRITE procedure to return NFS3ERR_FBIG. We believe that NFSv3 reference implementations also return NFS3ERR_FBIG when ia_size is too large.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.17:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.17:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.17:rc3:*:*:*:*:*:*

History

07 Oct 2025, 20:04

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/37f2d2cd8eadddbbd9c7bda327a9393399b2f89b - () https://git.kernel.org/stable/c/37f2d2cd8eadddbbd9c7bda327a9393399b2f89b - Patch
References () https://git.kernel.org/stable/c/72c14aed6838b5d90b4dd926b6a339b34bb02e08 - () https://git.kernel.org/stable/c/72c14aed6838b5d90b4dd926b6a339b34bb02e08 - Patch
References () https://git.kernel.org/stable/c/a231ae6bb50e7c0a9e9efd7b0d10687f1d71b3a3 - () https://git.kernel.org/stable/c/a231ae6bb50e7c0a9e9efd7b0d10687f1d71b3a3 - Patch
References () https://git.kernel.org/stable/c/a648fdeb7c0e17177a2280344d015dba3fbe3314 - () https://git.kernel.org/stable/c/a648fdeb7c0e17177a2280344d015dba3fbe3314 - Patch
References () https://git.kernel.org/stable/c/aa9051ddb4b378bd22e72a67bc77b9fc1482c5f0 - () https://git.kernel.org/stable/c/aa9051ddb4b378bd22e72a67bc77b9fc1482c5f0 - Patch
CWE NVD-CWE-noinfo
CPE cpe:2.3:o:linux:linux_kernel:5.17:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.17:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.17:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
First Time Linux
Linux linux Kernel

27 Jun 2025, 11:15

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/72c14aed6838b5d90b4dd926b6a339b34bb02e08 -

Information

Published : 2024-07-16 12:15

Updated : 2025-10-07 20:04


NVD link : CVE-2022-48829

Mitre link : CVE-2022-48829

CVE.ORG link : CVE-2022-48829


JSON object : View

Products Affected

linux

  • linux_kernel