tree f590dfaac5a52c1edda337cc22731d8a98ab1b1b
parent f5181ed34408da5932100dc30d6e392a847cd901
author Chuck Lever <chuck.lever@oracle.com> 1726589723 -0400
committer Kevin Berry <kpberry@google.com> 1736623014 -0800

NFSD: Prevent a potential integer overflow

commit 7f33b92e5b18e904a481e6e208486da43e4dc841 upstream.

If the tag length is >= U32_MAX - 3 then the "length + 4" addition
can result in an integer overflow. Address this by splitting the
decoding into several steps so that decode_cb_compound4res() does
not have to perform arithmetic on the unsafe length value.

BUG=b/388469395
TEST=presubmit
RELEASE_NOTE=Fixed CVE-2024-53146 in the Linux kernel.

cos-patch: security-moderate
Reported-by: Dan Carpenter <dan.carpenter@linaro.org>
Cc: stable@vger.kernel.org
Reviewed-by: Jeff Layton <jlayton@kernel.org>
Change-Id: I5ea1d505146d06a60c9dfa2c0e3b080f554a156e
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Kernel CVE Triage Automation <cloud-image-kernel-cve-triage-automation@prod.google.com>
Reviewed-on: https://cos-review.googlesource.com/c/third_party/kernel/+/89879
Tested-by: Cusky Presubmit Bot <presubmit@cos-infra-prod.iam.gserviceaccount.com>
Reviewed-by: Anil Altinay <aaltinay@google.com>
Reviewed-by: Kevin Berry <kpberry@google.com>
