Project

General

Profile

Actions

Bug #5145

closed
PA VJ

nfs: Integer underflow in NFS

Bug #5145: nfs: Integer underflow in NFS

Added by Philippe Antoine about 4 years ago. Updated almost 4 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:
Needs backport, Needs backport to 5.0, Needs backport to 6.0

Description

Found by ClusterFuzzLite, then oss-fuzz
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=44185

The whole NFSv3 logic for writes seems wrong (like ts_chunk_left should always be 0, we do not know the final size of the file)
This is not about the full filesize, but only about the current chunk that we're processing.


Related issues 3 (0 open3 closed)

Related to Suricata - Bug #5280: nfs: ASSERT: attempt to subtract with overflow (compound)ClosedPhilippe AntoineActions
Copied to Suricata - Bug #5149: nfs: Integer underflow in NFSClosedShivani BhardwajActions
Copied to Suricata - Bug #5150: nfs: Integer underflow in NFSClosedJason IshActions

VJ Updated by Victor Julien about 4 years ago Actions #1

  • Subject changed from Integer underflow in NFS to nfs: Integer underflow in NFS
  • Status changed from New to In Progress
  • Private changed from Yes to No

JL Updated by Jeff Lucovsky about 4 years ago Actions #2

  • Copied to Bug #5149: nfs: Integer underflow in NFS added

JL Updated by Jeff Lucovsky about 4 years ago Actions #3

  • Copied to Bug #5150: nfs: Integer underflow in NFS added

VJ Updated by Victor Julien about 4 years ago Actions #4

  • Status changed from In Progress to Closed

VJ Updated by Victor Julien about 4 years ago Actions #5

  • Description updated (diff)

PA Updated by Philippe Antoine almost 4 years ago Actions #6

  • Status changed from Closed to Assigned

VJ Updated by Victor Julien almost 4 years ago Actions #7

Closing in favor of a new ticket #5280 to not confuse the backports process.

VJ Updated by Victor Julien almost 4 years ago Actions #8

  • Status changed from Assigned to Closed

PA Updated by Philippe Antoine almost 4 years ago Actions #9

  • Related to Bug #5280: nfs: ASSERT: attempt to subtract with overflow (compound) added
Actions

Also available in: PDF Atom