kernel: NFSD: Protect against send buffer overflow in NFSv3 READDIR
Published Oct 4, 2025
7.5
HIGHCVSS 3.1
EPSS 0.02%
Description
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Affected products
No data.
No data.
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-425.13.1.el8_7
Fixed · RHSA-2023:0832
Red Hat Enterprise Linux 8
kernel-0:4.18.0-477.10.1.el8_8
Fixed · RHSA-2023:2951
Red Hat Enterprise Linux 9
kernel-0:5.14.0-284.11.1.el9_2
Fixed · RHSA-2023:2458
Red Hat Enterprise Linux 9
kernel-0:5.14.0-284.11.1.el9_2
Fixed · RHSA-2023:2458
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Affected
Red Hat Enterprise Linux 7
kernel-rt
Affected
Red Hat Enterprise Linux 8
kernel-rt
Affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-425.13.1.el8_7 | Fixed | RHSA-2023:0832 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-477.10.1.el8_8 | Fixed | RHSA-2023:2951 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-284.11.1.el9_2 | Fixed | RHSA-2023:2458 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-284.11.1.el9_2 | Fixed | RHSA-2023:2458 |
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
NFSD optimizes memory usage by sharing the same page array for both receiving RPC calls and sending replies, since operations typically don't need large buffers simultaneously. When an RPC call arrives, the response buffer size is calculated based on remaining pages after accounting for the received data. A malicious client can send a correctly-formed but deliberately oversized RPC record containing a small actual RPC call. The NFSD thread processes this normally, but the response buffer (rq_res) is now constrained. When constructing a READDIR reply, which can be quite large, the encoder writes past the truncated buffer boundary into adjacent kernel memory.
References (6)
- https://access.redhat.com/security/cve/CVE-2022-50487 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2401498 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-32365 Advisory
- https://lore.kernel.org/linux-cve-announce/2025100441-CVE-2022-50487-f5ea@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-50487
- https://www.cve.org/CVERecord?id=CVE-2022-50487
Change history (0)
No recorded changes yet.
CISA Vulnrichment
No data
GitHub
No data