Re: [NFS] [SECURITY] Re: NFSv3 for Linux 2.2.14: new release

From: Chris Evans (chris@ferret.lmh.ox.ac.uk)
Date: Thu Apr 20 2000 - 07:33:25 EST


On 20 Apr 2000, Trond Myklebust wrote:

> > +xdr_decode_fhstatus3(struct rpc_rqst *req, u32 *p, struct

> Serious security flaw? Well...
> That particular code is only meant to be used for mounting the NFSROOT
> partition, so if you receive an illegal file handle, your client isn't
> going to boot whether or not the memcpy messes up.

Oh OK, sorry. I thought it was a more general routine. Still, it
illustrates something the rest of the NFS code has to be careful about.

Cheers
Chris

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.rutgers.edu
Please read the FAQ at http://www.tux.org/lkml/



This archive was generated by hypermail 2b29 : Sun Apr 23 2000 - 21:00:17 EST