* [PATCH v2] nfsd: bounds-check opnum before testing spo_must_allow
@ 2026-09-30 5:54 Jinpyo Lee
2026-10-05 15:04 ` Chuck Lever
0 siblings, 1 reply; 2+ messages in thread
From: Jinpyo Lee @ 2026-09-30 5:54 UTC (permalink / raw)
To: linux-nfs
Cc: Chuck Lever, Jeff Layton, NeilBrown, Olga Kornievskaia, Dai Ngo,
Tom Talpey, Greg KH, bobtobabz, Jinpyo Lee
The NFSv4 decoder represents an unknown wire operation as OP_ILLEGAL,
whose value is outside struct nfs4_op_map. nfsd4_spo_must_allow() passes
that value directly to test_bit(), causing an out-of-bounds bitmap read
when an invalid operation follows a successfully processed operation.
For an SP4_MACH_CRED client, a set out-of-bounds bit also marks the
compound as spo_must_allowed. Validation used the nfsd-testing base
recorded below. On the unmodified KASAN kernel with an empty allow bitmap,
the out-of-bounds bit changed the export security-flavor result from
NFS4ERR_WRONGSEC to NFS4_OK for 64 of 72 client instances. A krb5i canary
read then succeeded through a sec=krb5p export. The current allocation
layout did not produce a KASAN report for this invalid bitmap access.
Reject operation numbers above LAST_NFS4_OP before testing the bitmap.
AUTH_NULL reaches the invalid load. The observed security-flavor decision
change additionally requires a valid SP4_MACH_CRED client and matching GSS
credentials; ordinary POSIX permissions remained enforced. Source
reproducers and complete logs are available privately on request. A legal
OP_CLOSE control also allowed the preceding read, so the read itself is
not claimed as a capability unique to this OOB.
With this patch, none of the 72 client instances caused the export
security-flavor check to return NFS4_OK for the invalid-operation probe,
and the canary read was denied. The legal OP_CLOSE and empty-bitmap
controls retained their expected behavior, and no KASAN report was
observed. The full KASAN kernel built with CONFIG_WERROR without a compiler
diagnostic. Basic NFSv4.2 and NFSv3 read/write/unmount smoke tests also
passed.
The vulnerability research and validation were conducted by members of
the Tobabz team as part of the Best of the Best 15th program.
Fixes: ed94164398c9 ("nfsd: implement machine credential support for some operations")
Assisted-by: LLM
Signed-off-by: Jinpyo Lee <bint4b13@gmail.com>
---
Changes in v2:
- Make the current policy impact and controls self-contained.
- Add full-build and NFSv4.2/NFSv3 smoke-test results.
- No code changes.
fs/nfsd/nfs4proc.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
diff --git a/fs/nfsd/nfs4proc.c b/fs/nfsd/nfs4proc.c
index 7df60abfb..f9e119cd0 100644
--- a/fs/nfsd/nfs4proc.c
+++ b/fs/nfsd/nfs4proc.c
@@ -4293,9 +4293,10 @@ bool nfsd4_spo_must_allow(struct svc_rqst *rqstp)
opiter = resp->opcnt;
while (opiter < argp->opcnt) {
this = &argp->ops[opiter++];
- if (test_bit(this->opnum, allow->u.longs) &&
- cstate->clp->cl_mach_cred &&
- nfsd4_mach_creds_match(cstate->clp, rqstp)) {
+ if (this->opnum <= LAST_NFS4_OP &&
+ test_bit(this->opnum, allow->u.longs) &&
+ cstate->clp->cl_mach_cred &&
+ nfsd4_mach_creds_match(cstate->clp, rqstp)) {
cstate->spo_must_allowed = true;
return true;
}
base-commit: 32eb1a60b456980761cf7a9cee8f907fdc08afb8
--
2.50.1 (Apple Git-155)
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [PATCH v2] nfsd: bounds-check opnum before testing spo_must_allow
2026-09-30 5:54 [PATCH v2] nfsd: bounds-check opnum before testing spo_must_allow Jinpyo Lee
@ 2026-10-05 15:04 ` Chuck Lever
0 siblings, 0 replies; 2+ messages in thread
From: Chuck Lever @ 2026-10-05 15:04 UTC (permalink / raw)
To: linux-nfs, Jinpyo Lee
Cc: Jeff Layton, NeilBrown, Olga Kornievskaia, Dai Ngo, Tom Talpey,
Greg KH, bobtobabz
On Wed, 30 Sep 2026 14:54:14 +0900, Jinpyo Lee wrote:
> The NFSv4 decoder represents an unknown wire operation as OP_ILLEGAL,
> whose value is outside struct nfs4_op_map. nfsd4_spo_must_allow() passes
> that value directly to test_bit(), causing an out-of-bounds bitmap read
> when an invalid operation follows a successfully processed operation.
>
> For an SP4_MACH_CRED client, a set out-of-bounds bit also marks the
> compound as spo_must_allowed. Validation used the nfsd-testing base
> recorded below. On the unmodified KASAN kernel with an empty allow bitmap,
> the out-of-bounds bit changed the export security-flavor result from
> NFS4ERR_WRONGSEC to NFS4_OK for 64 of 72 client instances. A krb5i canary
> read then succeeded through a sec=krb5p export. The current allocation
> layout did not produce a KASAN report for this invalid bitmap access.
>
> [...]
Applied, thanks!
[1/1] nfsd: bounds-check opnum before testing spo_must_allow
commit: 759d4bfd7697400acba1f66fd2dbba414f78a80f
Best regards,
--
Chuck Lever <cel@kernel.org>
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-10-05 15:04 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-30 5:54 [PATCH v2] nfsd: bounds-check opnum before testing spo_must_allow Jinpyo Lee
2026-10-05 15:04 ` Chuck Lever
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox