kern/60645: nfssvc(2): arithmetic overflow in input array sizing

"[email protected] via gnats" <[email protected]>
Newsgroups gmane.os.netbsd.bugs
Message-ID <[email protected]>
>Number:         60645
>Category:       kern
>Synopsis:       nfssvc(2): arithmetic overflow in input array sizing
>Confidential:   no
>Severity:       serious
>Priority:       medium
>Responsible:    kern-bug-people
>State:          open
>Class:          sw-bug
>Submitter-Id:   net
>Arrival-Date:   Wed Aug 26 02:10:00 +0000 2026
>Originator:     Taylor R Campbell
>Release:        current, 11, 10, 9, ...
>Organization:
The NetBSD Filexportation, In)3^=$,*%928:5%-%76)0
>Environment:
>Description:

	Unchecked multiplication for an array malloc can lead to
	overflow and various downstream consequences:

    343 	} else if (flag & (NFSSVC_SETEXPORTSLIST | NFSSVC_REPLACEEXPORTSLIST)) {
    344 		struct export_args *args;
    345 		struct mountd_exports_list mel;
    346 
    347 		error = ops->setexports_in(&mel, argp);
    348 		if (error != 0)
    349 			return error;
    350 
    351 		args = (struct export_args *)malloc(mel.mel_nexports *
    352 		    sizeof(struct export_args), M_TEMP, M_WAITOK);
    353 		error = ops->exp_in(args, mel.mel_exports, mel.mel_nexports);

	https://nxr.netbsd.org/xref/src/sys/nfs/nfs_syscalls.c?r=1.165#343

>How-To-Repeat:

	code inspection

	export a file system too many different ways

>Fix:

	set a maximum number of exports per mount point
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.