Re: [PATCH] nfsd: zero NFSv4 COMPOUND tag padding

From: Jeff Layton

Date: Tue Sep 15 2026 - 13:22:45 EST


On Tue, 2026-09-15 at 13:00 -0300, Aldo Ariel Panzardo wrote:
> nfs4svc_encode_compoundres() copies the tag bytes into reserved XDR space
> and skips directly to the aligned end of the field. xdr_reserve_space()
> rounds the reservation up but does not initialize the padding bytes.
>
> A remote client can choose a tag length that is not a multiple of four,
> causing one to three stale bytes from the response page to be returned in
> the COMPOUND reply.
>
> Use xdr_encode_opaque_fixed() to copy the tag and clear its XDR padding.
>
> Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Aldo Ariel Panzardo <qwe.aldo@xxxxxxxxx>
> ---
> fs/nfsd/nfs4xdr.c | 3 +--
> 1 file changed, 1 insertion(+), 2 deletions(-)
>
> diff --git a/fs/nfsd/nfs4xdr.c b/fs/nfsd/nfs4xdr.c
> index e17488a911..9377f42dfd 100644
> --- a/fs/nfsd/nfs4xdr.c
> +++ b/fs/nfsd/nfs4xdr.c
> @@ -6480,8 +6480,7 @@ nfs4svc_encode_compoundres(struct svc_rqst *rqstp, struct xdr_stream *xdr)
>
> *p++ = resp->cstate.status;
> *p++ = htonl(resp->taglen);
> - memcpy(p, resp->tag, resp->taglen);
> - p += XDR_QUADLEN(resp->taglen);
> + p = xdr_encode_opaque_fixed(p, resp->tag, resp->taglen);
> *p++ = htonl(resp->opcnt);
>
> nfsd4_sequence_done(resp);

Reviewed-by: Jeff Layton <jlayton@xxxxxxxxxx>