git: fac8422a41e6 - stable/13 - nfsd: Sanity check the Layouttype count
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Sat, 18 Dec 2021 01:36:10 UTC
The branch stable/13 has been updated by rmacklem:
URL: https://cgit.FreeBSD.org/src/commit/?id=fac8422a41e61847acd06f7dab9fab9cfc2f4a74
commit fac8422a41e61847acd06f7dab9fab9cfc2f4a74
Author: Rick Macklem <rmacklem@FreeBSD.org>
AuthorDate: 2021-12-04 22:18:48 +0000
Commit: Rick Macklem <rmacklem@FreeBSD.org>
CommitDate: 2021-12-18 01:32:47 +0000
nfsd: Sanity check the Layouttype count
PR: 260155
(cherry picked from commit 480be96e1e24617f0f152256d7453f60774fd1f3)
---
sys/fs/nfs/nfs_commonsubs.c | 9 +++++++++
1 file changed, 9 insertions(+)
diff --git a/sys/fs/nfs/nfs_commonsubs.c b/sys/fs/nfs/nfs_commonsubs.c
index 29e33372e83e..5a944ffa8c1a 100644
--- a/sys/fs/nfs/nfs_commonsubs.c
+++ b/sys/fs/nfs/nfs_commonsubs.c
@@ -2186,6 +2186,15 @@ nfsv4_loadattr(struct nfsrv_descript *nd, vnode_t vp,
NFSM_DISSECT(tl, u_int32_t *, NFSX_UNSIGNED);
attrsum += NFSX_UNSIGNED;
i = fxdr_unsigned(int, *tl);
+ /*
+ * The RFCs do not define an upper limit for the
+ * number of layout types, but 32 should be more
+ * than enough.
+ */
+ if (i < 0 || i > 32) {
+ error = NFSERR_BADXDR;
+ goto nfsmout;
+ }
if (i > 0) {
NFSM_DISSECT(tl, u_int32_t *, i *
NFSX_UNSIGNED);