In the Linux kernel, the following vulnerability has been resolved: nfsd: don't replace page in rq_pages if it's a continuation of last page The splice read calls nfsd_splice_actor to put the pages containing file data into the svc_rqst->rq_pages array. It's possible however to get a splice result that only has a partial page at the end, if (e.g.) the filesystem hands back a short read that doesn't cover the whole page. nfsd_splice_actor will plop the partial page into its rq_pages array and return. Then later, when nfsd_splice_actor is called again, the remainder of the page may end up being filled out. At this point, nfsd_splice_actor will put the page into the array _again_ corrupting the reply. If this is done enough times, rq_next_page will overrun the array and corrupt the trailing fields -- the rq_respages and rq_next_page pointers themselves. If we've already added the page to the array in the last pass, don't add it to the array a second time when dealing with a splice continuation. This was originally handled properly in nfsd_splice_actor, but commit 91e23b1c3982 ("NFSD: Clean up nfsd_splice_actor()") removed the check for it.
In the Linux kernel, the following vulnerability has been resolved: nfsd: don't replace page in rq_pages if it's a continuation of last page The splice read calls nfsd_splice_actor to put the pages containing file data into the svc_rqst->rq_pages array. It's possible however to get a splice result that only has a partial page at the end, if (e.g.) the filesystem hands back a short read that doesn't cover the whole page. nfsd_splice_actor will plop the partial page into its rq_pages array and return. Then later, when nfsd_splice_actor is called again, the remainder of the page may end up being filled out. At this point, nfsd_splice_actor will put the page into the array _again_ corrupting the reply. If this is done enough times, rq_next_page will overrun the array and corrupt the trailing fields -- the rq_respages and rq_next_page pointers themselves. If we've already added the page to the array in the last pass, don't add it to the array a second time when dealing with a splice continuation. This was originally handled properly in nfsd_splice_actor, but commit 91e23b1c3982 ("NFSD: Clean up nfsd_splice_actor()") removed the check for it.
Update Linux/Linux to 8235cd619db6e67f1d7d26c55f1f3e4e575c947d if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scannfsd: don't replace page in rq_pages if it's a continuation of last page affects Linux/Linux (generic), Linux/Linux (generic). Severity is critical. In the Linux kernel, the following vulnerability has been resolved: nfsd: don't replace page in rq_pages if it's a continuation of last page The splice read calls nfsd_splice_actor to put the pages containing file data into the svc_rqst->rq_pages array. It's possible however to get a splice result that only has a partial page at the end, if (e.g.) the filesystem hands back a short read that doesn't cover the whole page. nfsd_splice_actor will plop the partial page into its rq_pages array and return. Then later, when nfsd_splice_actor is called again, the remainder of the page may end up being filled out. At this point, nfsd_splice_actor will put the page into the array _again_ corrupting the reply. If this is done enough times, rq_next_page will overrun the array and corrupt the trailing fields -- the rq_respages and rq_next_page pointers themselves. If we've already added the page to the array in the last pass, don't add it to the array a second time when dealing with a splice continuation. This was originally handled properly in nfsd_splice_actor, but commit 91e23b1c3982 ("NFSD: Clean up nfsd_splice_actor()") removed the check for it.
AI coding agents often install or upgrade packages automatically in generic. A critical vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=bf1cbe2f3650b4f4a8add6af933c6d7f6af1f361 <8235cd619db6e67f1d7d26c55f1f3e4e575c947d || >=56bc7e3821e847a6cc8027ddaba32e9a440225a5 <12eca509234acb6b666802edf77408bb70d7bfca || >=91e23b1c39820bfed642119ff6b6ef9f43cf09ce <51ddb84baff6f09ad62b5999ece3ec172e4e3568 || >=91e23b1c39820bfed642119ff6b6ef9f43cf09ce <0101067f376eb7b9afd00279270f25d5111a091d || >=91e23b1c39820bfed642119ff6b6ef9f43cf09ce <27c934dd8832dd40fd34776f916dc201e18b319b | 8235cd619db6e67f1d7d26c55f1f3e4e575c947d, 12eca509234acb6b666802edf77408bb70d7bfca, 51ddb84baff6f09ad62b5999ece3ec172e4e3568, 0101067f376eb7b9afd00279270f25d5111a091d, 27c934dd8832dd40fd34776f916dc201e18b319b |
| Linux/Linuxgeneric | 5.19 | Not reported |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL GuardUpdate Linux/Linux to 8235cd619db6e67f1d7d26c55f1f3e4e575c947d if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scannfsd: don't replace page in rq_pages if it's a continuation of last page affects Linux/Linux (generic), Linux/Linux (generic). Severity is critical. In the Linux kernel, the following vulnerability has been resolved: nfsd: don't replace page in rq_pages if it's a continuation of last page The splice read calls nfsd_splice_actor to put the pages containing file data into the svc_rqst->rq_pages array. It's possible however to get a splice result that only has a partial page at the end, if (e.g.) the filesystem hands back a short read that doesn't cover the whole page. nfsd_splice_actor will plop the partial page into its rq_pages array and return. Then later, when nfsd_splice_actor is called again, the remainder of the page may end up being filled out. At this point, nfsd_splice_actor will put the page into the array _again_ corrupting the reply. If this is done enough times, rq_next_page will overrun the array and corrupt the trailing fields -- the rq_respages and rq_next_page pointers themselves. If we've already added the page to the array in the last pass, don't add it to the array a second time when dealing with a splice continuation. This was originally handled properly in nfsd_splice_actor, but commit 91e23b1c3982 ("NFSD: Clean up nfsd_splice_actor()") removed the check for it.
AI coding agents often install or upgrade packages automatically in generic. A critical vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=bf1cbe2f3650b4f4a8add6af933c6d7f6af1f361 <8235cd619db6e67f1d7d26c55f1f3e4e575c947d || >=56bc7e3821e847a6cc8027ddaba32e9a440225a5 <12eca509234acb6b666802edf77408bb70d7bfca || >=91e23b1c39820bfed642119ff6b6ef9f43cf09ce <51ddb84baff6f09ad62b5999ece3ec172e4e3568 || >=91e23b1c39820bfed642119ff6b6ef9f43cf09ce <0101067f376eb7b9afd00279270f25d5111a091d || >=91e23b1c39820bfed642119ff6b6ef9f43cf09ce <27c934dd8832dd40fd34776f916dc201e18b319b | 8235cd619db6e67f1d7d26c55f1f3e4e575c947d, 12eca509234acb6b666802edf77408bb70d7bfca, 51ddb84baff6f09ad62b5999ece3ec172e4e3568, 0101067f376eb7b9afd00279270f25d5111a091d, 27c934dd8832dd40fd34776f916dc201e18b319b |
| Linux/Linuxgeneric | 5.19 | Not reported |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard