* [PATCH v2] nfsd: hash only the supplied client-owner bytes
@ 2026-09-30 5:52 Jinpyo Lee
2026-10-01 0:45 ` Chuck Lever
0 siblings, 1 reply; 2+ messages in thread
From: Jinpyo Lee @ 2026-09-30 5:52 UTC (permalink / raw)
To: linux-nfs
Cc: Chuck Lever, Jeff Layton, NeilBrown, Olga Kornievskaia, Dai Ngo,
Tom Talpey, Willy Tarreau, bobtobabz, Jinpyo Lee
NFSv4 client-owner strings are variable-length XDR opaque data, but
clientstr_hashval() unconditionally hashes eight bytes. A valid owner
shorter than eight bytes therefore makes the reclaim lookup read beyond
the allocated string.
An ordinary NFSv4.1 client can supply a one-byte owner and issue
EXCHANGE_ID, CREATE_SESSION, and RECLAIM_COMPLETE during startup grace.
Generic KASAN reported a one-byte slab out-of-bounds read immediately
after the one-byte allocation in nfsd4_find_reclaim_client(). No
disclosure of the adjacent bytes or other production security impact was
demonstrated.
Pass name.len to opaque_hashval() so hashing is bounded by the length
validated by the XDR decoder.
Validation used the nfsd-testing base recorded below. On the unmodified
KASAN kernel, the one-byte client completed EXCHANGE_ID, CREATE_SESSION,
and RECLAIM_COMPLETE, then triggered the slab-out-of-bounds read in
nfsd4_find_reclaim_client(). With this patch, the same sequence returned
status 0 with two operations and produced no KASAN report.
The full KASAN kernel built with CONFIG_WERROR without a compiler
diagnostic. Basic NFSv4.2 and NFSv3 read/write/unmount smoke tests also
passed. A source reproducer and the complete KASAN logs are available
privately on request.
The vulnerability research and validation were conducted by members of
the Tobabz team as part of the Best of the Best 15th program.
Fixes: 6b1891052a3f ("nfsd: make nfs4_client_reclaim use an xdr_netobj instead of a fixed char array")
Assisted-by: LLM
Signed-off-by: Jinpyo Lee <bint4b13@gmail.com>
---
Changes in v2:
- Describe the baseline and patched runtime results explicitly.
- Add full-build and NFSv4.2/NFSv3 smoke-test results.
- No code changes.
fs/nfsd/nfs4state.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/fs/nfsd/nfs4state.c b/fs/nfsd/nfs4state.c
index bbc16dd22..e818c032a 100644
--- a/fs/nfsd/nfs4state.c
+++ b/fs/nfsd/nfs4state.c
@@ -1649,7 +1649,7 @@ static unsigned int clientid_hashval(u32 id)
static unsigned int clientstr_hashval(struct xdr_netobj name)
{
- return opaque_hashval(name.data, 8) & CLIENT_HASH_MASK;
+ return opaque_hashval(name.data, name.len) & CLIENT_HASH_MASK;
}
/*
base-commit: 32eb1a60b456980761cf7a9cee8f907fdc08afb8
--
2.50.1 (Apple Git-155)
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [PATCH v2] nfsd: hash only the supplied client-owner bytes
2026-09-30 5:52 [PATCH v2] nfsd: hash only the supplied client-owner bytes Jinpyo Lee
@ 2026-10-01 0:45 ` Chuck Lever
0 siblings, 0 replies; 2+ messages in thread
From: Chuck Lever @ 2026-10-01 0:45 UTC (permalink / raw)
To: Jinpyo Lee
Cc: linux-nfs, Jeff Layton, NeilBrown, Olga Kornievskaia, Dai Ngo,
Tom Talpey, Willy Tarreau, bobtobabz
Hi Jinpyo -
On Wed, Sep 30, 2026 at 02:52:35PM +0900, Jinpyo Lee wrote:
> Pass name.len to opaque_hashval() so hashing is bounded by the length
> validated by the XDR decoder.
Thanks for the report and the patch. Boyan Liu posted the same
one-line change to clientstr_hashval() on September 27:
https://lore.kernel.org/linux-nfs/20260927142319.12054-1-yymhvert@gmail.com/
I have already applied that patch to my private testing tree, so this
one is not needed.
--
Chuck Lever (Come to NFS bake-a-thon! https://nfsv4bat.org)
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-10-01 0:45 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-30 5:52 [PATCH v2] nfsd: hash only the supplied client-owner bytes Jinpyo Lee
2026-10-01 0:45 ` Chuck Lever
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox