Re: [PATCH v2] SUNRPC: restrict integrity replies to authenticated payload
From: Chuck Lever
Date: Tue Sep 22 2026 - 11:56:21 EST
On Sun, 20 Sep 2026 21:07:13 +0000, Jérémy Jean wrote:
> gss_unwrap_resp_integ() authenticates only databody_integ. The checksum
> object and any bytes after it are not covered by the integrity check, but
> remain visible to the XDR decoder.
>
> This makes RPCSEC_GSS reply payloads malleable by bypassing crypto
> integrity. A modified reply can contain only the RPCSEC_GSS sequence
> number in databody_integ, reuse the reply verifier MIC as the body MIC,
> and append bytes that the decoder consumes without invalidating the MIC.
>
> [...]
Applied to nfsd-testing, thanks!
[1/1] SUNRPC: restrict integrity replies to authenticated payload
(no commit info)
--
Chuck Lever