From fac8422a41e61847acd06f7dab9fab9cfc2f4a74 Mon Sep 17 00:00:00 2001 From: Rick Macklem Date: Sat, 4 Dec 2021 14:18:48 -0800 Subject: [PATCH] nfsd: Sanity check the Layouttype count PR: 260155 (cherry picked from commit 480be96e1e24617f0f152256d7453f60774fd1f3) --- sys/fs/nfs/nfs_commonsubs.c | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/sys/fs/nfs/nfs_commonsubs.c b/sys/fs/nfs/nfs_commonsubs.c index 29e33372e83..5a944ffa8c1 100644 --- a/sys/fs/nfs/nfs_commonsubs.c +++ b/sys/fs/nfs/nfs_commonsubs.c @@ -2186,6 +2186,15 @@ nfsv4_loadattr(struct nfsrv_descript *nd, vnode_t vp, NFSM_DISSECT(tl, u_int32_t *, NFSX_UNSIGNED); attrsum += NFSX_UNSIGNED; i = fxdr_unsigned(int, *tl); + /* + * The RFCs do not define an upper limit for the + * number of layout types, but 32 should be more + * than enough. + */ + if (i < 0 || i > 32) { + error = NFSERR_BADXDR; + goto nfsmout; + } if (i > 0) { NFSM_DISSECT(tl, u_int32_t *, i * NFSX_UNSIGNED);