Database/Control plane, storage & DevOps
Linux NFS server (nfsd, nfssvc_decode_writeargs): The NFSv2/v3 write argument decoder has no lower bound on the length
CVSS 9.8CVE-2022-49280Control plane, storage & DevOpscurated
Impact
The NFSv2/v3 write argument decoder has no lower bound on the length field, so a negative value underflows and the server reads or writes outside the intended buffer. Unauthenticated remote memory corruption in the kernel on the file server.
Who can reach it
Any host able to send NFS RPC to the server. No authentication needed.
What to do
Update the storage server kernel and reboot. If your workloads only need NFSv4, disable v2/v3 in /etc/nfs.conf (vers2=n, vers3=n) to remove this decoder from the reachable surface.
References
Related entries
- AMD SMM Supervisor (AMD-SB-7011): The highest-scored AMD platform CVE in this database at 9.8 critical. A flaw in theCVE-2023-20596 · AMD SMM Supervisor (AMD-SB-7011)Critical
- Fortinet FortiOS / FortiProxy SSL-VPN: A heap-based buffer overflow in the SSL-VPN daemon lets a remoteCVE-2023-27997 · Fortinet FortiOS / FortiProxy SSL-VPNCritical
- Progress MOVEit Transfer: Unauthenticated SQL injection into the web appCVE-2023-34362 · Progress MOVEit TransferCritical
- Citrix NetScaler ADC/Gateway: Unauthenticated remote code execution on the gateway applianceCVE-2023-3519 · Citrix NetScaler ADC/GatewayCritical
- JetBrains TeamCity: Authentication bypass leading to remote code execution on TeamCity ServerCVE-2023-42793 · JetBrains TeamCityCritical
- Acronis Cyber Infrastructure: Default passwordsCVE-2023-45249 · Acronis Cyber InfrastructureCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.