[PATCH] NFSv4.1: initialize referring call pointers before decoding

Jérémy Jean <[email protected]>
Newsgroups org.kernel.vger.linux-nfs,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
decode_cb_sequence_args() allocates csa_rclists with kmalloc_objs(), so
each referring_call_list starts uninitialized. decode_rc_list() assigns
rcl_refcalls only when rcl_nrefcalls is nonzero. A valid list with zero
referring calls therefore leaves the pointer uninitialized, and
nfs4_callback_sequence() later passes it to kfree(). KASAN reports a
double free in nfs_cb_sequence_empty_refcalls_test().

Initialize the pointer before decoding the list.

Fixes: 4aece6a19cf7 ("nfs41: cb_sequence xdr implementation")
Assisted-by: Codex:gpt-5
Signed-off-by: Jérémy Jean <[email protected]>
---
 fs/nfs/callback_xdr.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/fs/nfs/callback_xdr.c b/fs/nfs/callback_xdr.c
index 4382baddc9ee..5857f57f0644 100644
--- a/fs/nfs/callback_xdr.c
+++ b/fs/nfs/callback_xdr.c
@@ -360,6 +360,7 @@ static __be32 decode_rc_list(struct xdr_stream *xdr,
 	int i;
 	__be32 status;
 
+	rc_list->rcl_refcalls = NULL;
 	status = decode_sessionid(xdr, &rc_list->rcl_sessionid);
 	if (status)
 		goto out;
-- 
2.47.3
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.