Executive brief
A security vulnerability has been identified in the Linux kernel's Network File System (NFS) server component. This flaw allows a local user with standard privileges to write data to restricted memory areas that should be inaccessible. An attacker could exploit this to compromise the integrity of the system or access sensitive information, potentially leading to a full system takeover.
Technical details
An out-of-bounds (OOB) memory write flaw was discovered in the NFSD (NFS server) implementation within the Linux kernel. The vulnerability resides in the nfsd4_decode_bitmap4 function in fs/nfsd/nfs4xdr.c, where a lack of proper input validation allows a write beyond the allocated bmval array. A local attacker with user-level privileges can trigger this overflow via specially crafted RPC requests, specifically affecting nfsd4_decode_exchange_id() calls. This can lead to the corruption of kernel memory, threatening system confidentiality and integrity. The issue was addressed by rewriting the decoding loops to ensure they do not iterate beyond the defined bitmap length.
Affected products
- Linux Linux Kernel Fixed in 5.16-rc2
- Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem All versions
Timeline
- 2021-11-14: patched: Upstream patch submitted by Chuck Lever
- 2021-11-19: disclosed: Bug reported to Red Hat Bugzilla
- 2022-02-18: advisory: NVD publication date