From: Steve Dickson <steved@redhat.com>
To: Scott Mayhew <smayhew@redhat.com>
Cc: linux-nfs@vger.kernel.org
Subject: Re: [nfs-utils PATCH 2/2] junction: fix use-after-free in locations_to_fslocdata()
Date: Wed, 16 Sep 2026 10:11:47 -0400 [thread overview]
Message-ID: <a8dedaab-758f-4ea6-8adf-b2fcfa262e17@redhat.com> (raw)
In-Reply-To: <20260903175313.1214070-3-smayhew@redhat.com>
On 9/3/26 1:53 PM, Scott Mayhew wrote:
> While parsing a multi-location junction, locations_to_fslocdata() sets
> last_path = root_path and then frees root_path, leaving last_path
> dangling. On the next iteration, strcmp(rootpath, last_path)
> dereferences freed memory.
>
> Fix it by transferring ownership of root_path to last_path when they
> should be aliased.
>
> Signed-off-by: Scott Mayhew <smayhew@redhat.com>
Committed... (tag: nfs-utils-2-9-3-rc4)
steved.
> ---
> support/export/cache.c | 6 ++++++
> 1 file changed, 6 insertions(+)
>
> diff --git a/support/export/cache.c b/support/export/cache.c
> index 059f48a7..9f71c1dd 100644
> --- a/support/export/cache.c
> +++ b/support/export/cache.c
> @@ -2806,19 +2806,25 @@ static bool locations_to_fslocdata(struct nfs_fsloc_set *locations,
> }
> remaining -= (size_t)len;
> ptr += len;
> + free(last_path);
> last_path = rootpath;
> + rootpath = NULL;
> }
>
> seen = true;
> free(rootpath);
> + rootpath = NULL;
> free(server);
> + server = NULL;
> }
>
> + free(last_path);
> xlog(D_CALL, "%s: fslocdata='%s', ttl=%d",
> __func__, fslocdata, *ttl);
> return seen;
>
> out_false:
> + free(last_path);
> free(rootpath);
> free(server);
> return false;
prev parent reply other threads:[~2026-09-16 14:11 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-03 17:53 [nfs-utils PATCH 0/2] Two hardening fixes for junction handling Scott Mayhew
2026-09-03 17:53 ` [nfs-utils PATCH 1/2] junction: fix buffer over-read in junction_parse_xml_read() Scott Mayhew
2026-09-16 14:16 ` Steve Dickson
2026-09-03 17:53 ` [nfs-utils PATCH 2/2] junction: fix use-after-free in locations_to_fslocdata() Scott Mayhew
2026-09-16 14:11 ` Steve Dickson [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=a8dedaab-758f-4ea6-8adf-b2fcfa262e17@redhat.com \
--to=steved@redhat.com \
--cc=linux-nfs@vger.kernel.org \
--cc=smayhew@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox