Impact
In the Linux kernel’s NFSv4 server, time fields received in the TIME_DELEG_ACCESS and TIME_DELEG_MODIFY decode paths are copied directly into a timespec structure without checking that the nanoseconds component is less than one billion. A malicious NFS client can therefore send a timestamp with an out‑of‑range nanoseconds value. When this unchecked value propagates through a notify_change() call to the underlying filesystem, it can corrupt disk metadata, potentially leading to data loss or a crash of the NFS service. The weakness represents an input‑validation failure that compromises data integrity.
Affected Systems
All Linux kernels that provide the NFSv4 server and have not incorporated the upstream commit adding the range checks are affected. This includes every distribution running a kernel before the described fix, because the flaw resides in the core nfs4xdr and nfs4callback modules.
Risk and Exploitability
The CVSS score of 6.8 indicates a moderate severity and that an attacker with network access to the NFSv4 daemon could score of <1% suggests that exploitation is currently unlikely, and the vulnerability is not listed in CISA KEV. Nonetheless, the possibility of disk metadata corruption or service disruption makes the risk significant for hosts that accept untrusted NFS traffic.
OpenCVE Enrichment