aboutsummaryrefslogtreecommitdiff
path: root/lib
diff options
context:
space:
mode:
authorMark Johnston <markj@FreeBSD.org>2026-03-24 02:12:42 +0000
committerPhilip Paeps <philip@FreeBSD.org>2026-03-26 01:30:59 +0000
commitc4f53a1adbd4d5209b45043d25e590f0c27b5314 (patch)
tree3c4736da7c2ada2ab99d65bee64279db811eb3b9 /lib
parent9d3e842358b4b776a0e4bbab921695ac35f3baa3 (diff)
Diffstat (limited to 'lib')
-rw-r--r--lib/librpcsec_gss/svc_rpcsec_gss.c9
1 files changed, 8 insertions, 1 deletions
diff --git a/lib/librpcsec_gss/svc_rpcsec_gss.c b/lib/librpcsec_gss/svc_rpcsec_gss.c
index e9d39a813f86..73b92371e6d0 100644
--- a/lib/librpcsec_gss/svc_rpcsec_gss.c
+++ b/lib/librpcsec_gss/svc_rpcsec_gss.c
@@ -758,6 +758,14 @@ svc_rpc_gss_validate(struct svc_rpc_gss_client *client, struct rpc_msg *msg,
memset(rpchdr, 0, sizeof(rpchdr));
+ oa = &msg->rm_call.cb_cred;
+
+ if (oa->oa_length > sizeof(rpchdr) - 8 * BYTES_PER_XDR_UNIT) {
+ log_debug("auth length %d exceeds maximum", oa->oa_length);
+ client->cl_state = CLIENT_STALE;
+ return (FALSE);
+ }
+
/* Reconstruct RPC header for signing (from xdr_callmsg). */
buf = rpchdr;
IXDR_PUT_LONG(buf, msg->rm_xid);
@@ -766,7 +774,6 @@ svc_rpc_gss_validate(struct svc_rpc_gss_client *client, struct rpc_msg *msg,
IXDR_PUT_LONG(buf, msg->rm_call.cb_prog);
IXDR_PUT_LONG(buf, msg->rm_call.cb_vers);
IXDR_PUT_LONG(buf, msg->rm_call.cb_proc);
- oa = &msg->rm_call.cb_cred;
IXDR_PUT_ENUM(buf, oa->oa_flavor);
IXDR_PUT_LONG(buf, oa->oa_length);
if (oa->oa_length) {