aboutsummaryrefslogtreecommitdiff
path: root/sys
diff options
context:
space:
mode:
authorMark Johnston <markj@FreeBSD.org>2026-03-24 02:12:42 +0000
committerPhilip Paeps <philip@FreeBSD.org>2026-03-26 01:30:59 +0000
commitc4f53a1adbd4d5209b45043d25e590f0c27b5314 (patch)
tree3c4736da7c2ada2ab99d65bee64279db811eb3b9 /sys
parent9d3e842358b4b776a0e4bbab921695ac35f3baa3 (diff)
Diffstat (limited to 'sys')
-rw-r--r--sys/rpc/rpcsec_gss/svc_rpcsec_gss.c10
1 files changed, 9 insertions, 1 deletions
diff --git a/sys/rpc/rpcsec_gss/svc_rpcsec_gss.c b/sys/rpc/rpcsec_gss/svc_rpcsec_gss.c
index 93a41dc045cc..8e98a87b36be 100644
--- a/sys/rpc/rpcsec_gss/svc_rpcsec_gss.c
+++ b/sys/rpc/rpcsec_gss/svc_rpcsec_gss.c
@@ -1079,6 +1079,15 @@ svc_rpc_gss_validate(struct svc_rpc_gss_client *client, struct rpc_msg *msg,
memset(rpchdr, 0, sizeof(rpchdr));
+ oa = &msg->rm_call.cb_cred;
+
+ if (oa->oa_length > sizeof(rpchdr) - 8 * BYTES_PER_XDR_UNIT) {
+ rpc_gss_log_debug("auth length %d exceeds maximum",
+ oa->oa_length);
+ client->cl_state = CLIENT_STALE;
+ return (FALSE);
+ }
+
/* Reconstruct RPC header for signing (from xdr_callmsg). */
buf = rpchdr;
IXDR_PUT_LONG(buf, msg->rm_xid);
@@ -1087,7 +1096,6 @@ svc_rpc_gss_validate(struct svc_rpc_gss_client *client, struct rpc_msg *msg,
IXDR_PUT_LONG(buf, msg->rm_call.cb_prog);
IXDR_PUT_LONG(buf, msg->rm_call.cb_vers);
IXDR_PUT_LONG(buf, msg->rm_call.cb_proc);
- oa = &msg->rm_call.cb_cred;
IXDR_PUT_ENUM(buf, oa->oa_flavor);
IXDR_PUT_LONG(buf, oa->oa_length);
if (oa->oa_length) {