Date: Sat, 18 Dec 2021 01:45:13 GMT From: Rick Macklem <rmacklem@FreeBSD.org> To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org Subject: git: 5ad7804beb38 - stable/12 - nfsd: Sanity check the Layouttype count Message-ID: <202112180145.1BI1jDDO009121@gitrepo.freebsd.org>
next in thread | raw e-mail | index | archive | help
The branch stable/12 has been updated by rmacklem: URL: https://cgit.FreeBSD.org/src/commit/?id=5ad7804beb38fdc23f0f161484f5469e38c8fade commit 5ad7804beb38fdc23f0f161484f5469e38c8fade Author: Rick Macklem <rmacklem@FreeBSD.org> AuthorDate: 2021-12-04 22:18:48 +0000 Commit: Rick Macklem <rmacklem@FreeBSD.org> CommitDate: 2021-12-18 01:41:43 +0000 nfsd: Sanity check the Layouttype count PR: 260155 (cherry picked from commit 480be96e1e24617f0f152256d7453f60774fd1f3) --- sys/fs/nfs/nfs_commonsubs.c | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/sys/fs/nfs/nfs_commonsubs.c b/sys/fs/nfs/nfs_commonsubs.c index dcdf2e96c7e8..a11feaed3fcf 100644 --- a/sys/fs/nfs/nfs_commonsubs.c +++ b/sys/fs/nfs/nfs_commonsubs.c @@ -2155,6 +2155,15 @@ nfsv4_loadattr(struct nfsrv_descript *nd, vnode_t vp, NFSM_DISSECT(tl, u_int32_t *, NFSX_UNSIGNED); attrsum += NFSX_UNSIGNED; i = fxdr_unsigned(int, *tl); + /* + * The RFCs do not define an upper limit for the + * number of layout types, but 32 should be more + * than enough. + */ + if (i < 0 || i > 32) { + error = NFSERR_BADXDR; + goto nfsmout; + } if (i > 0) { NFSM_DISSECT(tl, u_int32_t *, i * NFSX_UNSIGNED);
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?202112180145.1BI1jDDO009121>