NFSD: Fix ia_size underflow
Published Jul 16, 2024
9.1
CRITICALCVSS 3.1
EPSS 0.63%
Description
iattr::ia_size is a loff_t, which is a signed 64-bit type. NFSv3 and NFSv4 both define file size as an unsigned 64-bit type. Thus there is a range of valid file size values an NFS client can send that is already larger than Linux can handle.
Currently decode_fattr4() dumps a full u64 value into ia_size. If that value happens to be larger than S64_MAX, then ia_size underflows. I'm about to fix up the NFSv3 behavior as well, so let's catch the underflow in the common code path: nfsd_setattr().
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 2.6.12StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<2.6.12
- Version 5.10.220StatusunaffectedConstraints<=5.10.*
- Version 5.15.24StatusunaffectedConstraints<=5.15.*
- Version 5.16.10StatusunaffectedConstraints<=5.16.*
- Version 5.17StatusunaffectedConstraints<=*
- Version 5.4.295StatusunaffectedConstraints<=5.4.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||
| Linux | Linux | affected |
|
- < 5.4.295
- ≥ 5.5 · < 5.10.220
- ≥ 5.11 · < 5.15.24
- ≥ 5.16 · < 5.16.10
- 5.17
- 5.17
- 5.17
No data.
Red Hat Enterprise Linux 8.2 Advanced Update Support
kernel-0:4.18.0-193.141.1.el8_2
Fixed · RHSA-2024:6992
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
kernel-0:4.18.0-305.138.1.el8_4
Fixed · RHSA-2024:5266
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
kernel-0:4.18.0-305.138.1.el8_4
Fixed · RHSA-2024:5266
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
kernel-rt-0:4.18.0-305.138.1.rt7.214.el8_4
Fixed · RHSA-2024:5282
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
kernel-0:4.18.0-305.138.1.el8_4
Fixed · RHSA-2024:5266
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
kernel-0:4.18.0-372.118.1.el8_6
Fixed · RHSA-2024:5281
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
kernel-0:4.18.0-372.118.1.el8_6
Fixed · RHSA-2024:5281
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
kernel-0:4.18.0-372.118.1.el8_6
Fixed · RHSA-2024:5281
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Affected
Red Hat Enterprise Linux 8
kernel-rt
Affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8.2 Advanced Update Support | kernel-0:4.18.0-193.141.1.el8_2 | Fixed | RHSA-2024:6992 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | kernel-0:4.18.0-305.138.1.el8_4 | Fixed | RHSA-2024:5266 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | kernel-0:4.18.0-305.138.1.el8_4 | Fixed | RHSA-2024:5266 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | kernel-rt-0:4.18.0-305.138.1.rt7.214.el8_4 | Fixed | RHSA-2024:5282 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | kernel-0:4.18.0-305.138.1.el8_4 | Fixed | RHSA-2024:5266 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | kernel-0:4.18.0-372.118.1.el8_6 | Fixed | RHSA-2024:5281 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | kernel-0:4.18.0-372.118.1.el8_6 | Fixed | RHSA-2024:5281 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | kernel-0:4.18.0-372.118.1.el8_6 | Fixed | RHSA-2024:5281 |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (12)
- https://access.redhat.com/security/cve/CVE-2022-48828 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2298167 Issue Tracking
- https://cert-portal.siemens.com/productcert/html/ssa-265688.html
- https://cert-portal.siemens.com/productcert/html/ssa-355557.html
- https://git.kernel.org/stable/c/38d02ba22e43b6fc7d291cf724bc6e3b7be6626b Patch
- https://git.kernel.org/stable/c/8e0ecaf7a7e57b30284d6b3289cc436100fadc48 Patch
- https://git.kernel.org/stable/c/d2211e6e34d0755f35e2f8c22d81999fa81cfc71 Patch
- https://git.kernel.org/stable/c/da22ca1ad548429d7822011c54cfe210718e0aa7 Patch
- https://git.kernel.org/stable/c/e6faac3f58c7c4176b66f63def17a34232a17b0e Patch
- https://lore.kernel.org/linux-cve-announce/2024071652-CVE-2022-48828-97cb@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-48828
- https://www.cve.org/CVERecord?id=CVE-2022-48828
Change history (0)
No recorded changes yet.