Impact
A Linux NFS server accepted an out-of-range nanosecond value in the NFSv3 SETATTR, CREATE, MKDIR, SYMLINK, or MKNOD operations without clamping it to the valid range. The value decoded cleanly on the wire but did not satisfy the internal timespec64 requirement that tv_nsec be less than NSEC_PER_SEC. As a result, the un- normalized timestamp was stored in inode metadata, causing integer overflows during on-disk encoding on filesystems that support nanosecond granularity such as ext4 and XFS. This overflow corrupted the epoch seconds stored in the filesystem, producing incorrect access and modification timestamps reflected to clients.
Affected Systems
The vulnerability is present in any Linux kernel that runs an NFS daemon with NFSv3 support. The affected product is the Linux kernel's NFS server component (nfsd). No specific kernel version ranges are provided, so all kernel revisions prior to the application of the patch are potentially affected.
Risk and Exploitability
The CVSS score is 6.8, indicating moderate severity. An EPSS score of <1% suggests that exploitation is unlikely to be widespread. The vulnerability is not listed in CISA’s KEV catalog. An attacker would typically be a remote NFSv3 client able to send a SETATTR, CREATE, MKDIR, SYMLINK, or MKNOD request with an out-of-range tv_nsec value. No special privileges are required on the client side, and the exploit cannot achieve code execution or privilege escalation. The primary risk is the corruption of inode timestamps, which can undermine data integrity and consistency for clients relying on accurate file times.
OpenCVE Enrichment
Debian DSA