NFSD: Fix NFSv3 SETATTR/CREATE's handling of large file sizes
Published Jul 16, 2024
9.1
CRITICALCVSS 3.1
EPSS 0.65%
Description
iattr::ia_size is a loff_t, so these NFSv3 procedures must be careful to deal with incoming client size values that are larger than s64_max without corrupting the value.
Silently capping the value results in storing a different value than the client passed in which is unexpected behavior, so remove the min_t() check in decode_sattr3().
Note that RFC 1813 permits only the WRITE procedure to return NFS3ERR_FBIG. We believe that NFSv3 reference implementations also return NFS3ERR_FBIG when ia_size is too large.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 2.6.12StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<2.6.12
- Version 5.10.220StatusunaffectedConstraints<=5.10.*
- Version 5.15.24StatusunaffectedConstraints<=5.15.*
- Version 5.16.10StatusunaffectedConstraints<=5.16.*
- Version 5.17StatusunaffectedConstraints<=*
- Version 5.4.295StatusunaffectedConstraints<=5.4.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||
| Linux | Linux | affected |
|
- < 5.4.295
- ≥ 5.5 · < 5.10.220
- ≥ 5.11 · < 5.15.24
- ≥ 5.16 · < 5.16.10
- 5.17
- 5.17
- 5.17
No data.
Red Hat Enterprise Linux 8.2 Advanced Update Support
kernel-0:4.18.0-193.141.1.el8_2
Fixed · RHSA-2024:6992
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
kernel-0:4.18.0-305.138.1.el8_4
Fixed · RHSA-2024:5266
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
kernel-0:4.18.0-305.138.1.el8_4
Fixed · RHSA-2024:5266
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
kernel-rt-0:4.18.0-305.138.1.rt7.214.el8_4
Fixed · RHSA-2024:5282
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
kernel-0:4.18.0-305.138.1.el8_4
Fixed · RHSA-2024:5266
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
kernel-0:4.18.0-372.118.1.el8_6
Fixed · RHSA-2024:5281
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
kernel-0:4.18.0-372.118.1.el8_6
Fixed · RHSA-2024:5281
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
kernel-0:4.18.0-372.118.1.el8_6
Fixed · RHSA-2024:5281
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Affected
Red Hat Enterprise Linux 8
kernel-rt
Affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8.2 Advanced Update Support | kernel-0:4.18.0-193.141.1.el8_2 | Fixed | RHSA-2024:6992 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | kernel-0:4.18.0-305.138.1.el8_4 | Fixed | RHSA-2024:5266 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | kernel-0:4.18.0-305.138.1.el8_4 | Fixed | RHSA-2024:5266 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | kernel-rt-0:4.18.0-305.138.1.rt7.214.el8_4 | Fixed | RHSA-2024:5282 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | kernel-0:4.18.0-305.138.1.el8_4 | Fixed | RHSA-2024:5266 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | kernel-0:4.18.0-372.118.1.el8_6 | Fixed | RHSA-2024:5281 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | kernel-0:4.18.0-372.118.1.el8_6 | Fixed | RHSA-2024:5281 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | kernel-0:4.18.0-372.118.1.el8_6 | Fixed | RHSA-2024:5281 |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (12)
- https://access.redhat.com/security/cve/CVE-2022-48829 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2298168 Issue Tracking
- https://cert-portal.siemens.com/productcert/html/ssa-265688.html
- https://cert-portal.siemens.com/productcert/html/ssa-355557.html
- https://git.kernel.org/stable/c/37f2d2cd8eadddbbd9c7bda327a9393399b2f89b Patch
- https://git.kernel.org/stable/c/72c14aed6838b5d90b4dd926b6a339b34bb02e08 Patch
- https://git.kernel.org/stable/c/a231ae6bb50e7c0a9e9efd7b0d10687f1d71b3a3 Patch
- https://git.kernel.org/stable/c/a648fdeb7c0e17177a2280344d015dba3fbe3314 Patch
- https://git.kernel.org/stable/c/aa9051ddb4b378bd22e72a67bc77b9fc1482c5f0 Patch
- https://lore.kernel.org/linux-cve-announce/2024071652-CVE-2022-48829-2145@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-48829
- https://www.cve.org/CVERecord?id=CVE-2022-48829
Change history (0)
No recorded changes yet.