Linux NFS development
 help / color / mirror / Atom feed
From: Jinpyo Lee <bint4b13@gmail.com>
To: linux-nfs@vger.kernel.org
Cc: Chuck Lever <cel@kernel.org>, Jeff Layton <jlayton@kernel.org>,
	NeilBrown <neil@brown.name>,
	Olga Kornievskaia <okorniev@redhat.com>,
	Dai Ngo <Dai.Ngo@oracle.com>, Tom Talpey <tom@talpey.com>,
	Willy Tarreau <w@1wt.eu>,
	bobtobabz@gmail.com, Jinpyo Lee <bint4b13@gmail.com>
Subject: [PATCH v2] nfsd: hash only the supplied client-owner bytes
Date: Wed, 30 Sep 2026 14:52:35 +0900	[thread overview]
Message-ID: <20260930055235.135503-1-bint4b13@gmail.com> (raw)

NFSv4 client-owner strings are variable-length XDR opaque data, but
clientstr_hashval() unconditionally hashes eight bytes. A valid owner
shorter than eight bytes therefore makes the reclaim lookup read beyond
the allocated string.

An ordinary NFSv4.1 client can supply a one-byte owner and issue
EXCHANGE_ID, CREATE_SESSION, and RECLAIM_COMPLETE during startup grace.
Generic KASAN reported a one-byte slab out-of-bounds read immediately
after the one-byte allocation in nfsd4_find_reclaim_client(). No
disclosure of the adjacent bytes or other production security impact was
demonstrated.

Pass name.len to opaque_hashval() so hashing is bounded by the length
validated by the XDR decoder.

Validation used the nfsd-testing base recorded below. On the unmodified
KASAN kernel, the one-byte client completed EXCHANGE_ID, CREATE_SESSION,
and RECLAIM_COMPLETE, then triggered the slab-out-of-bounds read in
nfsd4_find_reclaim_client(). With this patch, the same sequence returned
status 0 with two operations and produced no KASAN report.

The full KASAN kernel built with CONFIG_WERROR without a compiler
diagnostic. Basic NFSv4.2 and NFSv3 read/write/unmount smoke tests also
passed. A source reproducer and the complete KASAN logs are available
privately on request.

The vulnerability research and validation were conducted by members of
the Tobabz team as part of the Best of the Best 15th program.

Fixes: 6b1891052a3f ("nfsd: make nfs4_client_reclaim use an xdr_netobj instead of a fixed char array")
Assisted-by: LLM
Signed-off-by: Jinpyo Lee <bint4b13@gmail.com>
---
Changes in v2:
- Describe the baseline and patched runtime results explicitly.
- Add full-build and NFSv4.2/NFSv3 smoke-test results.
- No code changes.

 fs/nfsd/nfs4state.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/fs/nfsd/nfs4state.c b/fs/nfsd/nfs4state.c
index bbc16dd22..e818c032a 100644
--- a/fs/nfsd/nfs4state.c
+++ b/fs/nfsd/nfs4state.c
@@ -1649,7 +1649,7 @@ static unsigned int clientid_hashval(u32 id)
 
 static unsigned int clientstr_hashval(struct xdr_netobj name)
 {
-	return opaque_hashval(name.data, 8) & CLIENT_HASH_MASK;
+	return opaque_hashval(name.data, name.len) & CLIENT_HASH_MASK;
 }
 
 /*

base-commit: 32eb1a60b456980761cf7a9cee8f907fdc08afb8
-- 
2.50.1 (Apple Git-155)

             reply	other threads:[~2026-09-30  5:52 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-30  5:52 Jinpyo Lee [this message]
2026-10-01  0:45 ` [PATCH v2] nfsd: hash only the supplied client-owner bytes Chuck Lever

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260930055235.135503-1-bint4b13@gmail.com \
    --to=bint4b13@gmail.com \
    --cc=Dai.Ngo@oracle.com \
    --cc=bobtobabz@gmail.com \
    --cc=cel@kernel.org \
    --cc=jlayton@kernel.org \
    --cc=linux-nfs@vger.kernel.org \
    --cc=neil@brown.name \
    --cc=okorniev@redhat.com \
    --cc=tom@talpey.com \
    --cc=w@1wt.eu \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox