From: Olga Kornievskaia <okorniev@redhat.com>
To: steved@redhat.com
Cc: linux-nfs@vger.kernel.org
Subject: [PATCH 3/3] libtirpc: Bound maxsize in xdr_rpc_gss_unwrap_data() decode calls
Date: Sun, 6 Sep 2026 21:13:28 -0400 [thread overview]
Message-ID: <20260907011328.21425-4-okorniev@redhat.com> (raw)
In-Reply-To: <20260907011328.21425-1-okorniev@redhat.com>
xdr_rpc_gss_unwrap_data() passes (u_int)-1 as maxsize to
xdr_rpc_gss_buf() for all three decode calls (databody_integ,
checksum, databody_priv). This disables the length check in
xdr_bytes(), allowing a fabricated length field in a small RPC
message to trigger a multi-GB allocation before GSS verification.
Replace (u_int)-1 with RPCSEC_GSS_MAX_UNWRAP (16 MB). The encode
path already uses bounded values (wrapbuf.length + RPC_SLACK_SPACE).
Signed-off-by: Olga Kornievskaia <okorniev@redhat.com>
---
src/authgss_prot.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/src/authgss_prot.c b/src/authgss_prot.c
index c2b25db..c7de1fd 100644
--- a/src/authgss_prot.c
+++ b/src/authgss_prot.c
@@ -51,6 +51,9 @@
/* additional space needed for encoding */
#define RPC_SLACK_SPACE 1024
+/* upper bound on decoded RPCSEC_GSS wrapped payload (16 MB) */
+#define RPCSEC_GSS_MAX_UNWRAP (16U * 1024U * 1024U)
+
bool_t
xdr_rpc_gss_buf(XDR *xdrs, gss_buffer_t buf, u_int maxsize)
{
@@ -227,12 +230,12 @@ xdr_rpc_gss_unwrap_data(XDR *xdrs, xdrproc_t xdr_func, caddr_t xdr_ptr,
if (svc == RPCSEC_GSS_SVC_INTEGRITY) {
/* Decode databody_integ. */
- if (!xdr_rpc_gss_buf(xdrs, &databuf, (u_int)-1)) {
+ if (!xdr_rpc_gss_buf(xdrs, &databuf, RPCSEC_GSS_MAX_UNWRAP)) {
LIBTIRPC_DEBUG(1, ("xdr_rpc_gss_unwrap_data: decode databody_integ failed"));
return (FALSE);
}
/* Decode checksum. */
- if (!xdr_rpc_gss_buf(xdrs, &wrapbuf, (u_int)-1)) {
+ if (!xdr_rpc_gss_buf(xdrs, &wrapbuf, RPCSEC_GSS_MAX_UNWRAP)) {
gss_release_buffer(&min_stat, &databuf);
LIBTIRPC_DEBUG(1, ("xdr_rpc_gss_unwrap_data: decode checksum failed"));
return (FALSE);
--
2.52.0
next prev parent reply other threads:[~2026-09-07 1:13 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-07 1:13 [PATCH 1/1] fsidd: require root credentials on abstract socket Olga Kornievskaia
2026-09-07 1:13 ` [PATCH 1/3] libtirpc: Fix use-after-free in xdr_pmaplist() XDR_FREE path Olga Kornievskaia
2026-09-13 3:48 ` Steve Dickson
2026-09-07 1:13 ` [PATCH 2/3] libtirpc: limit XDR decode node count Olga Kornievskaia
2026-09-13 3:48 ` Steve Dickson
2026-09-07 1:13 ` Olga Kornievskaia [this message]
2026-09-13 3:49 ` [PATCH 3/3] libtirpc: Bound maxsize in xdr_rpc_gss_unwrap_data() decode calls Steve Dickson
2026-09-13 3:47 ` [PATCH 1/1] fsidd: require root credentials on abstract socket Steve Dickson
2026-09-16 14:19 ` Steve Dickson
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260907011328.21425-4-okorniev@redhat.com \
--to=okorniev@redhat.com \
--cc=linux-nfs@vger.kernel.org \
--cc=steved@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.