Back

CRITICAL

NFSD: Fix ia_size underflow

Published Jul 16, 2024

Description

iattr::ia_size is a loff_t, which is a signed 64-bit type. NFSv3 and NFSv4 both define file size as an unsigned 64-bit type. Thus there is a range of valid file size values an NFS client can send that is already larger than Linux can handle.

Currently decode_fattr4() dumps a full u64 value into ia_size. If that value happens to be larger than S64_MAX, then ia_size underflows. I'm about to fix up the NFSv3 behavior as well, so let's catch the underflow in the common code path: nfsd_setattr().

Affected products

Remediation

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Weaknesses (1)

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Jul 16, 2024
Updated Aug 5, 2026
Reserved Jul 16, 2024
CISA Vulnrichment
Updated Sep 10, 2024
NVD
Status Modified
Modified Aug 4, 2026
Red Hat
Severity Moderate
Public date Jul 16, 2024