Description
The Linux kernel NFSD implementation prior to versions 5.19.17 and 6.0.2 are vulnerable to buffer overflow. NFSD tracks the number of pages held by each NFSD thread by combining the receive and send buffers of a remote procedure call (RPC) into a single array of pages. A client can force the send buffer to shrink by sending an RPC message over TCP with garbage data added at the end of the message. The RPC message with garbage data is still correctly formed according to the specification and is passed forward to handlers. Vulnerable code in NFSD is not expecting the oversized request and writes beyond the allocated buffer space. CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5730-1 | linux security update |
EUVD |
EUVD-2022-46915 | The Linux kernel NFSD implementation prior to versions 5.19.17 and 6.0.2 are vulnerable to buffer overflow. NFSD tracks the number of pages held by each NFSD thread by combining the receive and send buffers of a remote procedure call (RPC) into a single array of pages. A client can force the send buffer to shrink by sending an RPC message over TCP with garbage data added at the end of the message. The RPC message with garbage data is still correctly formed according to the specification and is passed forward to handlers. Vulnerable code in NFSD is not expecting the oversized request and writes beyond the allocated buffer space. CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Ubuntu USN |
USN-5754-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-5754-2 | Linux kernel (Azure) vulnerabilities |
Ubuntu USN |
USN-5755-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-5755-2 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-5773-1 | Linux kernel (OEM) vulnerabilities |
Ubuntu USN |
USN-5779-1 | Linux kernel (Azure) vulnerabilities |
Ubuntu USN |
USN-5789-1 | Linux kernel (OEM) vulnerabilities |
Ubuntu USN |
USN-5794-1 | Linux kernel (AWS) vulnerabilities |
Ubuntu USN |
USN-5802-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-5804-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-5804-2 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-5808-1 | Linux kernel (IBM) vulnerabilities |
Ubuntu USN |
USN-5813-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-5829-1 | Linux kernel (Raspberry Pi) vulnerabilities |
Ubuntu USN |
USN-5830-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-5861-1 | Linux kernel (Dell300x) vulnerabilities |
Ubuntu USN |
USN-5863-1 | Linux kernel (Azure) vulnerabilities |
Ubuntu USN |
USN-5875-1 | Linux kernel (GKE) vulnerabilities |
Ubuntu USN |
USN-5914-1 | Linux kernel (OEM) vulnerabilities |
Ubuntu USN |
USN-5918-1 | Linux kernel (BlueField) vulnerabilities |
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 01 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Linux
Subscribe
Linux Kernel
Subscribe
Netapp
Subscribe
Active Iq Unified Manager
Subscribe
H300s
Subscribe
H300s Firmware
Subscribe
H410c
Subscribe
H410c Firmware
Subscribe
H410s
Subscribe
H410s Firmware
Subscribe
H500s
Subscribe
H500s Firmware
Subscribe
H700s
Subscribe
H700s Firmware
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Rhel Eus
Subscribe
Status: PUBLISHED
Assigner: SNPS
Published:
Updated: 2025-05-01T19:08:43.378Z
Reserved: 2022-10-26T00:00:00.000Z
Link: CVE-2022-43945
Updated: 2024-08-03T13:40:06.873Z
Status : Modified
Published: 2022-11-04T19:15:11.180
Modified: 2025-05-01T19:15:55.283
Link: CVE-2022-43945
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN