Project

General

Profile

Actions

Bug #5280

closed

nfs: ASSERT: attempt to subtract with overflow (compound)

Added by Victor Julien over 2 years ago. Updated almost 2 years ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
Label:


Files

nfs.pcap (701 Bytes) nfs.pcap Philippe Antoine, 04/25/2022 12:04 PM

Subtasks 1 (0 open1 closed)

Bug #5760: nfs: ASSERT: attempt to subtract with overflow (compound) (6.0.x backport)ClosedVictor JulienActions

Related issues 1 (0 open1 closed)

Related to Suricata - Bug #5145: nfs: Integer underflow in NFSClosedVictor JulienActions
Actions #1

Updated by Victor Julien over 2 years ago

  • Status changed from New to Assigned
  • Assignee changed from OISF Dev to Philippe Antoine

Philippe can you attach a pcap to reproduce?

Actions #2

Updated by Philippe Antoine over 2 years ago

Here it is.
To get a pcap from a fuzz_applayerparserparse_* input, I needed to
- Change the header to use fuzzpcap's one
- Use the right ports number for the app-layer protocol being fuzzed (nfs is 2049 0x0801)
- Add a first payload so that app-layer protocol is recognized
- Add acking packets...

Actions #3

Updated by Philippe Antoine over 2 years ago

  • Related to Bug #5145: nfs: Integer underflow in NFS added
Actions #4

Updated by Philippe Antoine over 2 years ago

  • Assignee changed from Philippe Antoine to Victor Julien

Looks like commit 4418fc1b02f47533439fe00789d9c850a24271b2 did not correct nfs4 but only nfs3

Victor, as you did that nfs3: fix partial write record handling, can you do it for NFS4 ?

Actions #5

Updated by Philippe Antoine over 2 years ago

Victor, do you want to pass this to me ?

Actions #6

Updated by Victor Julien over 2 years ago

  • Assignee changed from Victor Julien to Philippe Antoine
Actions #7

Updated by Philippe Antoine over 2 years ago

  • Status changed from Assigned to In Review
Actions #8

Updated by Philippe Antoine over 2 years ago

  • Status changed from In Review to Closed
Actions #9

Updated by Victor Julien about 2 years ago

  • Status changed from Closed to Resolved
Actions #10

Updated by Victor Julien about 2 years ago

  • Subtask #5760 added
Actions #11

Updated by Victor Julien about 2 years ago

  • Private changed from Yes to No
Actions #12

Updated by Victor Julien almost 2 years ago

  • Status changed from Resolved to Closed
Actions

Also available in: Atom PDF