Re: [PATCH] SUNRPC: check rpc_sockaddr2uaddr() return value in rpcb_register_inet4/6

Jeff Layton <[email protected]>
Newsgroups gmane.linux.network,gmane.linux.nfs,gmane.linux.kernel
Message-ID <[email protected]>
On Sun, 2026-06-07 at 07:06 -0700, Weiming Shi wrote:
> rpcb_register_inet4() and rpcb_register_inet6() store the result of
> rpc_sockaddr2uaddr() into map->r_addr without checking it for NULL.
> rpc_sockaddr2uaddr() returns NULL when its final kstrdup() fails, and
> the unchecked NULL is then carried into the synchronous RPCBPROC_SET
> encode path: rpcb_register_call() -> rpc_call_sync() ->
> rpcb_enc_getaddr() -> encode_rpcb_string(), whose first statement is
> strlen(string), dereferencing NULL and oopsing the kernel.
> 
> The crash reproduces under failslab on v6.12; with KASAN the NULL
> dereference surfaces as a fault on the shadow of address zero:
> 
>  Oops: general protection fault, probably for non-canonical address
>        0xdffffc0000000000 [#1] PREEMPT SMP KASAN
>  RIP: 0010:strlen (lib/string.c:409)
>  Call Trace:
>   encode_rpcb_string (net/sunrpc/rpcb_clnt.c:890)
>   rpcb_enc_getaddr (net/sunrpc/rpcb_clnt.c:910)
>   rpcauth_wrap_req_encode (net/sunrpc/auth.c:745)
>   call_encode (net/sunrpc/clnt.c:1966)
>   __rpc_execute (net/sunrpc/sched.c:952)
>   rpc_run_task (net/sunrpc/clnt.c:1243)
>   rpc_call_sync (net/sunrpc/clnt.c:1272)
>   rpcb_v4_register (net/sunrpc/rpcb_clnt.c:500)
>   svc_generic_rpcbind_set
>   nfsd_rpcbind_set
>   svc_register
>   svc_setup_socket
>   svc_addsock
>   write_ports
>   nfsctl_transaction_write
>   vfs_write
> 
> The crash is reachable when an in-kernel RPC service (nfsd, lockd,
> nfs-callback) registers with the local rpcbind under enough memory
> pressure for the small GFP_KERNEL kstrdup() in rpc_sockaddr2uaddr() to
> fail. The asynchronous getport path already handles this exact failure
> mode by returning -ENOMEM; only the two register helpers omit the check.
> 
> Mirror that handling: bail out with -ENOMEM when rpc_sockaddr2uaddr()
> returns NULL, before the address is fed into the encoder.
> 
> Fixes: d77385f23830 ("SUNRPC: Fix rpc_sockaddr2uaddr")
> Reported-by: Xiang Mei <[email protected]>
> Assisted-by: Claude:claude-opus-4-8
> Signed-off-by: Weiming Shi <[email protected]>
> ---
>  net/sunrpc/rpcb_clnt.c | 4 ++++
>  1 file changed, 4 insertions(+)
> 
> diff --git a/net/sunrpc/rpcb_clnt.c b/net/sunrpc/rpcb_clnt.c
> index 6aa372188c86..4c0b7fefee4e 100644
> --- a/net/sunrpc/rpcb_clnt.c
> +++ b/net/sunrpc/rpcb_clnt.c
> @@ -490,6 +490,8 @@ static int rpcb_register_inet4(struct sunrpc_net *sn,
>  	int result;
>  
>  	map->r_addr = rpc_sockaddr2uaddr(sap, GFP_KERNEL);
> +	if (!map->r_addr)
> +		return -ENOMEM;
>  
>  	msg->rpc_proc = &rpcb_procedures4[RPCBPROC_UNSET];
>  	if (port != 0) {
> @@ -516,6 +518,8 @@ static int rpcb_register_inet6(struct sunrpc_net *sn,
>  	int result;
>  
>  	map->r_addr = rpc_sockaddr2uaddr(sap, GFP_KERNEL);
> +	if (!map->r_addr)
> +		return -ENOMEM;
>  
>  	msg->rpc_proc = &rpcb_procedures4[RPCBPROC_UNSET];
>  	if (port != 0) {

Reviewed-by: Jeff Layton <[email protected]>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.