Impact
The vulnerability lies in the NFSv2 server’s attribute decoder, which converts a microseconds value sent in a SETATTR or CREATE request into nanoseconds by multiplying the 32‑bit value by 1,000. On 32‑bit (ILP32) kernels this multiplication can overflow when the client supplies a value larger than 1,000,000, producing a wrapped nanosecond value that appears valid. The server accepts the corrupted timestamp, writes it to the underlying filesystem, and later rejects the request with an RPC GARBAGE_ARGS reply. The flaw corrupts time metadata and causes denial of NFSv2 operations but does not enable code execution or data exfiltration.
Affected Systems
All Linux kernel distributions that ship if an NFSv2 server is enabled and reachable. Any system running a kernel older than the fix and serving NFSv2 traffic is affected, regardless of distribution vendor. The impact applies only when the NFSv2 protocol is enabled on the server; disabling NFSv2 or using a newer protocol version removes the vulnerability.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity, while the EPSS score of less than 1% suggests that actual exploitation is currently unlikely. The flaw is not yet listed in the CISA KEV catalog, implying no widespread exploitation has been observed. Based on the description, attackers can send crafted SETATTR or CREATE RPCs to an exposed NFSv2 service over the network, causing timestamp corruption and request denial. The analysis does not specify authentication requirements; therefore it is inferred that the vulnerability can be exploited against any host that accepts NFSv2 requests, regardless of whether those requests are authenticated.
OpenCVE Enrichment
Debian DSA