Back

HIGH

kernel: NFSD: Protect against send buffer overflow in NFSv3 READDIR

Published Oct 4, 2025

Description

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Affected products

Remediation

Red Hat statement

NFSD optimizes memory usage by sharing the same page array for both receiving RPC calls and sending replies, since operations typically don't need large buffers simultaneously. When an RPC call arrives, the response buffer size is calculated based on remaining pages after accounting for the received data. A malicious client can send a correctly-formed but deliberately oversized RPC record containing a small actual RPC call. The NFSD thread processes this normally, but the response buffer (rq_res) is now constrained. When constructing a READDIR reply, which can be quite large, the encoder writes past the truncated buffer boundary into adjacent kernel memory.

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Published Oct 4, 2025

CISA Vulnrichment

No data

NVD

Status Rejected
Modified Oct 10, 2025

Red Hat

Severity Moderate
Public date Oct 4, 2025
Bugzilla 2401498

ENISA EUVD

Assigner Linux
Published Oct 4, 2025
Updated Oct 10, 2025

GitHub

No data