[UBUNTU OEM-6.0 0/2] CVE-2022-43945

Thadeu Lima de Souza Cascardo cascardo at canonical.com
Fri Jan 27 18:32:19 UTC 2023


[Impact]
A malicious client can cause a buffer overflow on the nfsd server by sending
a crafted RPC message.

[Backport]
Missing two commits on 6.0 that were already applied to other kernels.

[Potential regression]
NFSD servers might misbehave.

Chuck Lever (2):
  NFSD: Remove "inline" directives on op_rsize_bop helpers
  NFSD: Cap rsize_bop result based on send buffer size

 fs/nfsd/nfs4proc.c | 169 ++++++++++++++++++++++++++-------------------
 fs/nfsd/xdr4.h     |   3 +-
 2 files changed, 101 insertions(+), 71 deletions(-)

-- 
2.34.1




More information about the kernel-team mailing list