* Re: CVE-2022-50455: nfs: fix possible null-ptr-deref when parsing param
[not found] <2025100118-CVE-2022-50455-24fb@gregkh>
@ 2025-10-10 2:19 ` Wang Zhaolong
2025-10-10 15:30 ` Greg Kroah-Hartman
0 siblings, 1 reply; 2+ messages in thread
From: Wang Zhaolong @ 2025-10-10 2:19 UTC (permalink / raw)
To: cve, linux-kernel, linux-cve-announce; +Cc: Greg Kroah-Hartman
> From: Greg Kroah-Hartman <gregkh@kernel.org>
>
> Description
> ===========
>
> In the Linux kernel, the following vulnerability has been resolved:
>
> nfs: fix possible null-ptr-deref when parsing param
>
> According to commit "vfs: parse: deal with zero length string value",
> kernel will set the param->string to null pointer in vfs_parse_fs_string()
> if fs string has zero length.
>
Hi Greg,
The patch "vfs: parse: deal with zero length string value", which introduced
this issue, was never merged into mainline.
It only exists in the mailing list:
https://lists.openwall.net/linux-kernel/2022/06/28/18
Since the problematic behavior never existed in any released kernel,
CVE-2022-50455 cannot be valid.
Please consider rejecting this CVE.
Best regards,
Wang Zhaolong
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: CVE-2022-50455: nfs: fix possible null-ptr-deref when parsing param
2025-10-10 2:19 ` CVE-2022-50455: nfs: fix possible null-ptr-deref when parsing param Wang Zhaolong
@ 2025-10-10 15:30 ` Greg Kroah-Hartman
0 siblings, 0 replies; 2+ messages in thread
From: Greg Kroah-Hartman @ 2025-10-10 15:30 UTC (permalink / raw)
To: Wang Zhaolong; +Cc: cve, linux-kernel, linux-cve-announce
On Fri, Oct 10, 2025 at 10:19:40AM +0800, Wang Zhaolong wrote:
>
>
>
>
> > From: Greg Kroah-Hartman <gregkh@kernel.org>
> >
> > Description
> > ===========
> >
> > In the Linux kernel, the following vulnerability has been resolved:
> >
> > nfs: fix possible null-ptr-deref when parsing param
> >
> > According to commit "vfs: parse: deal with zero length string value",
> > kernel will set the param->string to null pointer in vfs_parse_fs_string()
> > if fs string has zero length.
> >
>
> Hi Greg,
>
> The patch "vfs: parse: deal with zero length string value", which introduced
> this issue, was never merged into mainline.
>
> It only exists in the mailing list:
> https://lists.openwall.net/linux-kernel/2022/06/28/18
Please always use lore.kernel.org for emails, I had to go dig out the
whole thread from there based on that to determine what happened here :(
> Since the problematic behavior never existed in any released kernel,
> CVE-2022-50455 cannot be valid.
>
> Please consider rejecting this CVE.
Makes sense, I'll go reject this now, thanks for the review!
greg k-h
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2025-10-10 15:30 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
[not found] <2025100118-CVE-2022-50455-24fb@gregkh>
2025-10-10 2:19 ` CVE-2022-50455: nfs: fix possible null-ptr-deref when parsing param Wang Zhaolong
2025-10-10 15:30 ` Greg Kroah-Hartman
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®