CVE-2022-48827
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2022-48827 affects the Linux kernel's NFS server implementation. The vulnerability was discovered when a client attempts to read from an offset near OFFSET_MAX, causing a potential infinite retry loop. The issue stems from the NFS server returning an EINVAL error code that the client does not properly handle (NVD).

Technical details

The vulnerability occurs due to a commit that aligns buffers to RPC read layers on the client side. When a client reads 0xfff bytes, it gets aligned up to server rsize of 0x1000. If the server has a file of size 0x7fffffffffffffff and the client attempts to read from offset 0x7ffffffffffff000, it causes an lofft overflow in the server. This results in the server returning an NFSERR_INVAL code, which the Linux NFS client does not handle properly despite this being a valid response according to NFS specifications (Kernel Commit).

Impact

When exploited, this vulnerability causes the NFS client to enter an infinite retry loop when attempting to read files near the maximum offset size. This can lead to resource exhaustion and potential denial of service conditions (Red Hat).

Mitigation and workarounds

The fix modifies the server behavior to handle out-of-range READ requests by succeeding and returning a short result instead of NFSERRINVAL. The EOF flag is set in the result to prevent the client from retrying the READ request. This approach is consistent with Solaris NFS servers' behavior. The patch also ensures proper conversion of u64 offset values to loff_t internally (Kernel Commit).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40205HIGH7.8
  • Linux KernelLinux Kernel
  • linux-gcp-5.4
NoYesNov 12, 2025
CVE-2025-40211HIGH7.1
  • Linux KernelLinux Kernel
  • linux-gcp-6.8
NoYesNov 21, 2025
CVE-2025-40206MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-zfcpdump-modules-extra
NoYesNov 12, 2025
CVE-2025-40210MEDIUM5.1
  • Linux KernelLinux Kernel
  • kernel-rt-64k-modules
NoYesNov 21, 2025
CVE-2025-40212N/AN/A
  • Linux KernelLinux Kernel
  • linux-azure-6.14
NoYesNov 24, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management