In the Linux kernel, the following vulnerability has been resolved: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache The NFSv4.0 replay cache uses a fixed 112-byte inline buffer (rp_ibuf[NFSD4_REPLAY_ISIZE]) to store encoded operation responses. This size was calculated based on OPEN responses and does not account for LOCK denied responses, which include the conflicting lock owner as a variable-length field up to 1024 bytes (NFS4_OPAQUE_LIMIT). When a LOCK operation is denied due to a conflict with an existing lock that has a large owner, nfsd4_encode_operation() copies the full encoded response into the undersized replay buffer via read_bytes_from_xdr_buf() with no bounds check. This results in a slab-out-of-bounds write of up to 944 bytes past the end of the buffer, corrupting adjacent heap memory. This can be triggered remotely by an unauthenticated attacker with two cooperating NFSv4.0 clients: one sets a lock with a large owner string, then the other requests a conflicting lock to provoke the denial. We could fix this by increasing NFSD4_REPLAY_ISIZE to allow for a full opaque, but that would increase the size of every stateowner, when most lockowners are not that large. Instead, fix this by checking the encoded response length against NFSD4_REPLAY_ISIZE before copying into the replay buffer. If the response is too large, set rp_buflen to 0 to skip caching the replay payload. The status is still cached, and the client already received the correct response on the original request.
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: nfsd: corregir desbordamiento de montículo en la caché de repetición LOCK de NFSv4.0 La caché de repetición de NFSv4.0 utiliza un búfer en línea fijo de 112 bytes (rp_ibuf[NFSD4_REPLAY_ISIZE]) para almacenar respuestas de operaciones codificadas. Este tamaño se calculó basándose en respuestas OPEN y no tiene en cuenta las respuestas LOCK denegadas, que incluyen al propietario del bloqueo en conflicto como un campo de longitud variable de hasta 1024 bytes (NFS4_OPAQUE_LIMIT). Cuando una operación LOCK es denegada debido a un conflicto con un bloqueo existente que tiene un propietario grande, nfsd4_encode_operation() copia la respuesta codificada completa en el búfer de repetición de tamaño insuficiente a través de read_bytes_from_xdr_buf() sin verificación de límites. Esto resulta en una escritura fuera de límites de slab de hasta 944 bytes más allá del final del búfer, corrompiendo la memoria de montículo adyacente. Esto puede ser activado remotamente por un atacante no autenticado con dos clientes NFSv4.0 cooperantes: uno establece un bloqueo con una cadena de propietario grande, luego el otro solicita un bloqueo en conflicto para provocar la denegación. Podríamos corregir esto aumentando NFSD4_REPLAY_ISIZE para permitir un opaco completo, pero eso aumentaría el tamaño de cada propietario de estado, cuando la mayoría de los propietarios de bloqueo no son tan grandes. En su lugar, corregir esto verificando la longitud de la respuesta codificada contra NFSD4_REPLAY_ISIZE antes de copiarla en el búfer de repetición. Si la respuesta es demasiado grande, establecer rp_buflen en 0 para omitir el almacenamiento en caché de la carga útil de repetición. El estado aún se almacena en caché, y el cliente ya recibió la respuesta correcta en la solicitud original.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
Source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Type: Secondary
Exploitability Score: 3.9
Impact Score: 5.9
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
CWE-787
|
| 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | Secondary |
en
CWE-787
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d2357ccef00> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d2357b4d0c0> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d2357ccf580> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d2357ccc3c0> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d242a707900> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d23a59aa840> | Operating System |
| linux | linux_kernel | 2.6.12 | <built-in method update of dict object at 0x7d2357b4ea00> | Operating System |
| linux | linux_kernel | 2.6.12 | <built-in method update of dict object at 0x7d2357b4ff40> | Operating System |
| linux | linux_kernel | 2.6.12 | <built-in method update of dict object at 0x7d2357b4c080> | Operating System |
| linux | linux_kernel | 2.6.12 | <built-in method update of dict object at 0x7d23a59aa500> | Operating System |
| linux | linux_kernel | 2.6.12 | <built-in method update of dict object at 0x7d2357b4c4c0> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d2357b4fd00> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d24602fed00> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d23a5390e80> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d2357b4df00> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:2.6.12:-:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:2.6.12:rc2:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:2.6.12:rc3:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:* |