[PATCH] nfsd: zero NFSv4 COMPOUND tag padding
From: Aldo Ariel Panzardo
Date: Tue Sep 15 2026 - 12:30:34 EST
nfs4svc_encode_compoundres() copies the tag bytes into reserved XDR space
and skips directly to the aligned end of the field. xdr_reserve_space()
rounds the reservation up but does not initialize the padding bytes.
A remote client can choose a tag length that is not a multiple of four,
causing one to three stale bytes from the response page to be returned in
the COMPOUND reply.
Use xdr_encode_opaque_fixed() to copy the tag and clear its XDR padding.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Aldo Ariel Panzardo <qwe.aldo@xxxxxxxxx>
---
fs/nfsd/nfs4xdr.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/fs/nfsd/nfs4xdr.c b/fs/nfsd/nfs4xdr.c
index e17488a911..9377f42dfd 100644
--- a/fs/nfsd/nfs4xdr.c
+++ b/fs/nfsd/nfs4xdr.c
@@ -6480,8 +6480,7 @@ nfs4svc_encode_compoundres(struct svc_rqst *rqstp, struct xdr_stream *xdr)
*p++ = resp->cstate.status;
*p++ = htonl(resp->taglen);
- memcpy(p, resp->tag, resp->taglen);
- p += XDR_QUADLEN(resp->taglen);
+ p = xdr_encode_opaque_fixed(p, resp->tag, resp->taglen);
*p++ = htonl(resp->opcnt);
nfsd4_sequence_done(resp);
--
2.43.0