* [nfs-utils PATCH 0/2] Two hardening fixes for junction handling @ 2026-09-03 17:53 Scott Mayhew 2026-09-03 17:53 ` [nfs-utils PATCH 1/2] junction: fix buffer over-read in junction_parse_xml_read() Scott Mayhew 2026-09-03 17:53 ` [nfs-utils PATCH 2/2] junction: fix use-after-free in locations_to_fslocdata() Scott Mayhew 0 siblings, 2 replies; 5+ messages in thread From: Scott Mayhew @ 2026-09-03 17:53 UTC (permalink / raw) To: steved; +Cc: linux-nfs The first patch fixes a buffer overrun in junction_parse_xml_read() and the second fixes a use-after-free when parsing multi-location junctions in locations_to_fslocdata(). Scott Mayhew (2): junction: fix buffer over-read in junction_parse_xml_read() junction: fix use-after-free in locations_to_fslocdata() support/export/cache.c | 6 ++++++ support/junction/junction.c | 3 ++- 2 files changed, 8 insertions(+), 1 deletion(-) -- 2.55.0 ^ permalink raw reply [flat|nested] 5+ messages in thread
* [nfs-utils PATCH 1/2] junction: fix buffer over-read in junction_parse_xml_read() 2026-09-03 17:53 [nfs-utils PATCH 0/2] Two hardening fixes for junction handling Scott Mayhew @ 2026-09-03 17:53 ` Scott Mayhew 2026-09-16 14:16 ` Steve Dickson 2026-09-03 17:53 ` [nfs-utils PATCH 2/2] junction: fix use-after-free in locations_to_fslocdata() Scott Mayhew 1 sibling, 1 reply; 5+ messages in thread From: Scott Mayhew @ 2026-09-03 17:53 UTC (permalink / raw) To: steved; +Cc: linux-nfs junction_get_xattr() returns an opaque buffer, but junction_parse_xml_read() treats it as a string by passing it to xlog(). Fix it by allocating an extra byte and null-terminating the buffer in junction_get_xattr(). Signed-off-by: Scott Mayhew <smayhew@redhat.com> --- support/junction/junction.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/support/junction/junction.c b/support/junction/junction.c index c1ec8ff8..04a8ebf1 100644 --- a/support/junction/junction.c +++ b/support/junction/junction.c @@ -293,7 +293,7 @@ junction_get_xattr(int fd, const char *path, const char *name, void **contents, return FEDFS_ERR_ACCESS; } - xattrbuf = malloc((size_t)len); + xattrbuf = malloc((size_t)len + 1); if (xattrbuf == NULL) { xlog(D_GENERAL, "%s: failed to get buffer for xattr %s on %s", __func__, name, path); @@ -307,6 +307,7 @@ junction_get_xattr(int fd, const char *path, const char *name, void **contents, return FEDFS_ERR_ACCESS; } + ((char *) xattrbuf)[len] = '\0'; xlog(D_CALL, "%s: read xattr %s from path %s", __func__, name, path); *contents = xattrbuf; -- 2.55.0 ^ permalink raw reply related [flat|nested] 5+ messages in thread
* Re: [nfs-utils PATCH 1/2] junction: fix buffer over-read in junction_parse_xml_read() 2026-09-03 17:53 ` [nfs-utils PATCH 1/2] junction: fix buffer over-read in junction_parse_xml_read() Scott Mayhew @ 2026-09-16 14:16 ` Steve Dickson 0 siblings, 0 replies; 5+ messages in thread From: Steve Dickson @ 2026-09-16 14:16 UTC (permalink / raw) To: Scott Mayhew; +Cc: linux-nfs On 9/3/26 1:53 PM, Scott Mayhew wrote: > junction_get_xattr() returns an opaque buffer, but > junction_parse_xml_read() treats it as a string by passing it to xlog(). > Fix it by allocating an extra byte and null-terminating the buffer in > junction_get_xattr(). > > Signed-off-by: Scott Mayhew <smayhew@redhat.com> Committed... (tag: nfs-utils-2-9-3-rc4) steved. > --- > support/junction/junction.c | 3 ++- > 1 file changed, 2 insertions(+), 1 deletion(-) > > diff --git a/support/junction/junction.c b/support/junction/junction.c > index c1ec8ff8..04a8ebf1 100644 > --- a/support/junction/junction.c > +++ b/support/junction/junction.c > @@ -293,7 +293,7 @@ junction_get_xattr(int fd, const char *path, const char *name, void **contents, > return FEDFS_ERR_ACCESS; > } > > - xattrbuf = malloc((size_t)len); > + xattrbuf = malloc((size_t)len + 1); > if (xattrbuf == NULL) { > xlog(D_GENERAL, "%s: failed to get buffer for xattr %s on %s", > __func__, name, path); > @@ -307,6 +307,7 @@ junction_get_xattr(int fd, const char *path, const char *name, void **contents, > return FEDFS_ERR_ACCESS; > } > > + ((char *) xattrbuf)[len] = '\0'; > xlog(D_CALL, "%s: read xattr %s from path %s", > __func__, name, path); > *contents = xattrbuf; ^ permalink raw reply [flat|nested] 5+ messages in thread
* [nfs-utils PATCH 2/2] junction: fix use-after-free in locations_to_fslocdata() 2026-09-03 17:53 [nfs-utils PATCH 0/2] Two hardening fixes for junction handling Scott Mayhew 2026-09-03 17:53 ` [nfs-utils PATCH 1/2] junction: fix buffer over-read in junction_parse_xml_read() Scott Mayhew @ 2026-09-03 17:53 ` Scott Mayhew 2026-09-16 14:11 ` Steve Dickson 1 sibling, 1 reply; 5+ messages in thread From: Scott Mayhew @ 2026-09-03 17:53 UTC (permalink / raw) To: steved; +Cc: linux-nfs While parsing a multi-location junction, locations_to_fslocdata() sets last_path = root_path and then frees root_path, leaving last_path dangling. On the next iteration, strcmp(rootpath, last_path) dereferences freed memory. Fix it by transferring ownership of root_path to last_path when they should be aliased. Signed-off-by: Scott Mayhew <smayhew@redhat.com> --- support/export/cache.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/support/export/cache.c b/support/export/cache.c index 059f48a7..9f71c1dd 100644 --- a/support/export/cache.c +++ b/support/export/cache.c @@ -2806,19 +2806,25 @@ static bool locations_to_fslocdata(struct nfs_fsloc_set *locations, } remaining -= (size_t)len; ptr += len; + free(last_path); last_path = rootpath; + rootpath = NULL; } seen = true; free(rootpath); + rootpath = NULL; free(server); + server = NULL; } + free(last_path); xlog(D_CALL, "%s: fslocdata='%s', ttl=%d", __func__, fslocdata, *ttl); return seen; out_false: + free(last_path); free(rootpath); free(server); return false; -- 2.55.0 ^ permalink raw reply related [flat|nested] 5+ messages in thread
* Re: [nfs-utils PATCH 2/2] junction: fix use-after-free in locations_to_fslocdata() 2026-09-03 17:53 ` [nfs-utils PATCH 2/2] junction: fix use-after-free in locations_to_fslocdata() Scott Mayhew @ 2026-09-16 14:11 ` Steve Dickson 0 siblings, 0 replies; 5+ messages in thread From: Steve Dickson @ 2026-09-16 14:11 UTC (permalink / raw) To: Scott Mayhew; +Cc: linux-nfs On 9/3/26 1:53 PM, Scott Mayhew wrote: > While parsing a multi-location junction, locations_to_fslocdata() sets > last_path = root_path and then frees root_path, leaving last_path > dangling. On the next iteration, strcmp(rootpath, last_path) > dereferences freed memory. > > Fix it by transferring ownership of root_path to last_path when they > should be aliased. > > Signed-off-by: Scott Mayhew <smayhew@redhat.com> Committed... (tag: nfs-utils-2-9-3-rc4) steved. > --- > support/export/cache.c | 6 ++++++ > 1 file changed, 6 insertions(+) > > diff --git a/support/export/cache.c b/support/export/cache.c > index 059f48a7..9f71c1dd 100644 > --- a/support/export/cache.c > +++ b/support/export/cache.c > @@ -2806,19 +2806,25 @@ static bool locations_to_fslocdata(struct nfs_fsloc_set *locations, > } > remaining -= (size_t)len; > ptr += len; > + free(last_path); > last_path = rootpath; > + rootpath = NULL; > } > > seen = true; > free(rootpath); > + rootpath = NULL; > free(server); > + server = NULL; > } > > + free(last_path); > xlog(D_CALL, "%s: fslocdata='%s', ttl=%d", > __func__, fslocdata, *ttl); > return seen; > > out_false: > + free(last_path); > free(rootpath); > free(server); > return false; ^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-09-16 14:16 UTC | newest] Thread overview: 5+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2026-09-03 17:53 [nfs-utils PATCH 0/2] Two hardening fixes for junction handling Scott Mayhew 2026-09-03 17:53 ` [nfs-utils PATCH 1/2] junction: fix buffer over-read in junction_parse_xml_read() Scott Mayhew 2026-09-16 14:16 ` Steve Dickson 2026-09-03 17:53 ` [nfs-utils PATCH 2/2] junction: fix use-after-free in locations_to_fslocdata() Scott Mayhew 2026-09-16 14:11 ` Steve Dickson
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox