The branch stable/12 has been updated by rmacklem:

URL: 
https://cgit.FreeBSD.org/src/commit/?id=5ad7804beb38fdc23f0f161484f5469e38c8fade

commit 5ad7804beb38fdc23f0f161484f5469e38c8fade
Author:     Rick Macklem <rmack...@freebsd.org>
AuthorDate: 2021-12-04 22:18:48 +0000
Commit:     Rick Macklem <rmack...@freebsd.org>
CommitDate: 2021-12-18 01:41:43 +0000

    nfsd: Sanity check the Layouttype count
    
    PR:     260155
    
    (cherry picked from commit 480be96e1e24617f0f152256d7453f60774fd1f3)
---
 sys/fs/nfs/nfs_commonsubs.c | 9 +++++++++
 1 file changed, 9 insertions(+)

diff --git a/sys/fs/nfs/nfs_commonsubs.c b/sys/fs/nfs/nfs_commonsubs.c
index dcdf2e96c7e8..a11feaed3fcf 100644
--- a/sys/fs/nfs/nfs_commonsubs.c
+++ b/sys/fs/nfs/nfs_commonsubs.c
@@ -2155,6 +2155,15 @@ nfsv4_loadattr(struct nfsrv_descript *nd, vnode_t vp,
                        NFSM_DISSECT(tl, u_int32_t *, NFSX_UNSIGNED);
                        attrsum += NFSX_UNSIGNED;
                        i = fxdr_unsigned(int, *tl);
+                       /*
+                        * The RFCs do not define an upper limit for the
+                        * number of layout types, but 32 should be more
+                        * than enough.
+                        */
+                       if (i < 0 || i > 32) {
+                               error = NFSERR_BADXDR;
+                               goto nfsmout;
+                       }
                        if (i > 0) {
                                NFSM_DISSECT(tl, u_int32_t *, i *
                                    NFSX_UNSIGNED);

Reply via email to