Re: [PATCH] nfsd: Fix out-of-bounds read in clientstr_hashval()

From: Chuck Lever

Date: Mon Oct 05 2026 - 10:59:43 EST



On Sun, 27 Sep 2026 22:23:19 +0800, Boyan Liu wrote:
> clientstr_hashval() always hashes 8 bytes of the client name, but
> since commit 6b1891052a3f ("nfsd: make nfs4_client_reclaim use an
> xdr_netobj instead of a fixed char array") the name is a
> kmemdup()'d xdr_netobj of arbitrary length. A 1-7 byte ownerid is
> legal, so the hash reads past the allocation:
>
> BUG: KASAN: slab-out-of-bounds in nfsd4_find_reclaim_client
> Read of size 1 at addr ffff888010acf1a1 by task nfsd/141
> Call Trace:
> kasan_report (mm/kasan/report.c:595)
> nfsd4_find_reclaim_client (fs/nfsd/nfs4state.c:1622)
> nfsd4_reclaim_complete (fs/nfsd/nfs4state.c:5286)
> nfsd4_proc_compound (fs/nfsd/nfs4proc.c:3313)
> nfsd_dispatch (fs/nfsd/nfssvc.c:1038)
> svc_process_common (net/sunrpc/svc.c:1527)
> svc_process (net/sunrpc/svc.c:1682)
> svc_recv (net/sunrpc/svc_xprt.c:886)
> nfsd (fs/nfsd/nfssvc.c:919)
>
> [...]

Applied, thanks!

[1/1] nfsd: Fix out-of-bounds read in clientstr_hashval()
commit: bd3622da433d2f6cecc10a49f559383e0e13654b

Best regards,
--
Chuck Lever <cel@xxxxxxxxxx>