mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* Re: CVE-2022-50455: nfs: fix possible null-ptr-deref when parsing param
       [not found] <2025100118-CVE-2022-50455-24fb@gregkh>
@ 2025-10-10  2:19 ` Wang Zhaolong
  2025-10-10 15:30   ` Greg Kroah-Hartman
  0 siblings, 1 reply; 2+ messages in thread
From: Wang Zhaolong @ 2025-10-10  2:19 UTC (permalink / raw)
  To: cve, linux-kernel, linux-cve-announce; +Cc: Greg Kroah-Hartman





> From: Greg Kroah-Hartman <gregkh@kernel.org>
> 
> Description
> ===========
> 
> In the Linux kernel, the following vulnerability has been resolved:
> 
> nfs: fix possible null-ptr-deref when parsing param
> 
> According to commit "vfs: parse: deal with zero length string value",
> kernel will set the param->string to null pointer in vfs_parse_fs_string()
> if fs string has zero length.
> 

Hi Greg,

The patch "vfs: parse: deal with zero length string value", which introduced
this issue, was never merged into mainline.

It only exists in the mailing list:
https://lists.openwall.net/linux-kernel/2022/06/28/18

Since the problematic behavior never existed in any released kernel,
CVE-2022-50455 cannot be valid.

Please consider rejecting this CVE.

Best regards,
Wang Zhaolong


^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: CVE-2022-50455: nfs: fix possible null-ptr-deref when parsing param
  2025-10-10  2:19 ` CVE-2022-50455: nfs: fix possible null-ptr-deref when parsing param Wang Zhaolong
@ 2025-10-10 15:30   ` Greg Kroah-Hartman
  0 siblings, 0 replies; 2+ messages in thread
From: Greg Kroah-Hartman @ 2025-10-10 15:30 UTC (permalink / raw)
  To: Wang Zhaolong; +Cc: cve, linux-kernel, linux-cve-announce

On Fri, Oct 10, 2025 at 10:19:40AM +0800, Wang Zhaolong wrote:
> 
> 
> 
> 
> > From: Greg Kroah-Hartman <gregkh@kernel.org>
> > 
> > Description
> > ===========
> > 
> > In the Linux kernel, the following vulnerability has been resolved:
> > 
> > nfs: fix possible null-ptr-deref when parsing param
> > 
> > According to commit "vfs: parse: deal with zero length string value",
> > kernel will set the param->string to null pointer in vfs_parse_fs_string()
> > if fs string has zero length.
> > 
> 
> Hi Greg,
> 
> The patch "vfs: parse: deal with zero length string value", which introduced
> this issue, was never merged into mainline.
> 
> It only exists in the mailing list:
> https://lists.openwall.net/linux-kernel/2022/06/28/18

Please always use lore.kernel.org for emails, I had to go dig out the
whole thread from there based on that to determine what happened here :(

> Since the problematic behavior never existed in any released kernel,
> CVE-2022-50455 cannot be valid.
> 
> Please consider rejecting this CVE.

Makes sense, I'll go reject this now, thanks for the review!

greg k-h

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2025-10-10 15:30 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
     [not found] <2025100118-CVE-2022-50455-24fb@gregkh>
2025-10-10  2:19 ` CVE-2022-50455: nfs: fix possible null-ptr-deref when parsing param Wang Zhaolong
2025-10-10 15:30   ` Greg Kroah-Hartman

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®