Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Thu, 22 Oct 2009 12:58:21 +0800
From: Eugene Teo <>
CC: "Steven M. Christey" <>
Subject: CVE request: kernel: nfsd4: fix null dereference creating nfsv4 callback

Quoting from upstream patch:
"On setting up the callback to the client, we attempt to use the same
authentication flavor the client did.  We find an rpc cred to use by 
calling rpcauth_lookup_credcache(), which assumes that the given 
authentication flavor has a credentials cache.  However, this is not 
required to be true--in particular, auth_null does not use one. Instead, 
we should call the auth's lookup_cred() method.

Without this, a client attempting to mount using nfsv4 and auth_null 
triggers a null dereference."

The code was introduced in upstream commit 3cef9ab2 (v2.6.31-rc1), fixed 
in 886e3b7f (v2.6.32-rc1), and was later replaced by 80fc015b in the 
same version.


Thanks, Eugene

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.