diff options
author | Chuck Lever <chuck.lever@oracle.com> | 2022-09-01 15:09:59 -0400 |
---|---|---|
committer | Chuck Lever <chuck.lever@oracle.com> | 2022-09-26 14:02:26 -0400 |
commit | 1242a87da0d8cd2a428e96ca68e7ea899b0f4624 (patch) | |
tree | 0b6ec5907606e0c5607c204e47658c62838ff275 /include/linux/aio.h | |
parent | 90bfc37b5ab91c1a6165e3e5cfc49bf04571b762 (diff) | |
download | linux-stable-1242a87da0d8cd2a428e96ca68e7ea899b0f4624.tar.gz linux-stable-1242a87da0d8cd2a428e96ca68e7ea899b0f4624.tar.bz2 linux-stable-1242a87da0d8cd2a428e96ca68e7ea899b0f4624.zip |
SUNRPC: Fix svcxdr_init_encode's buflen calculation
Commit 2825a7f90753 ("nfsd4: allow encoding across page boundaries")
added an explicit computation of the remaining length in the rq_res
XDR buffer.
The computation appears to suffer from an "off-by-one" bug. Because
buflen is too large by one page, XDR encoding can run off the end of
the send buffer by eventually trying to use the struct page address
in rq_page_end, which always contains NULL.
Fixes: bddfdbcddbe2 ("NFSD: Extract the svcxdr_init_encode() helper")
Reviewed-by: Jeff Layton <jlayton@kernel.org>
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
Diffstat (limited to 'include/linux/aio.h')
0 files changed, 0 insertions, 0 deletions