* Re: CVE-2022-50455: nfs: fix possible null-ptr-deref when parsing param [not found] <2025100118-CVE-2022-50455-24fb@gregkh> @ 2025-10-10 2:19 ` Wang Zhaolong 2025-10-10 15:30 ` Greg Kroah-Hartman 0 siblings, 1 reply; 2+ messages in thread From: Wang Zhaolong @ 2025-10-10 2:19 UTC (permalink / raw) To: cve, linux-kernel, linux-cve-announce; +Cc: Greg Kroah-Hartman > From: Greg Kroah-Hartman <gregkh@kernel.org> > > Description > =========== > > In the Linux kernel, the following vulnerability has been resolved: > > nfs: fix possible null-ptr-deref when parsing param > > According to commit "vfs: parse: deal with zero length string value", > kernel will set the param->string to null pointer in vfs_parse_fs_string() > if fs string has zero length. > Hi Greg, The patch "vfs: parse: deal with zero length string value", which introduced this issue, was never merged into mainline. It only exists in the mailing list: https://lists.openwall.net/linux-kernel/2022/06/28/18 Since the problematic behavior never existed in any released kernel, CVE-2022-50455 cannot be valid. Please consider rejecting this CVE. Best regards, Wang Zhaolong ^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: CVE-2022-50455: nfs: fix possible null-ptr-deref when parsing param 2025-10-10 2:19 ` CVE-2022-50455: nfs: fix possible null-ptr-deref when parsing param Wang Zhaolong @ 2025-10-10 15:30 ` Greg Kroah-Hartman 0 siblings, 0 replies; 2+ messages in thread From: Greg Kroah-Hartman @ 2025-10-10 15:30 UTC (permalink / raw) To: Wang Zhaolong; +Cc: cve, linux-kernel, linux-cve-announce On Fri, Oct 10, 2025 at 10:19:40AM +0800, Wang Zhaolong wrote: > > > > > > From: Greg Kroah-Hartman <gregkh@kernel.org> > > > > Description > > =========== > > > > In the Linux kernel, the following vulnerability has been resolved: > > > > nfs: fix possible null-ptr-deref when parsing param > > > > According to commit "vfs: parse: deal with zero length string value", > > kernel will set the param->string to null pointer in vfs_parse_fs_string() > > if fs string has zero length. > > > > Hi Greg, > > The patch "vfs: parse: deal with zero length string value", which introduced > this issue, was never merged into mainline. > > It only exists in the mailing list: > https://lists.openwall.net/linux-kernel/2022/06/28/18 Please always use lore.kernel.org for emails, I had to go dig out the whole thread from there based on that to determine what happened here :( > Since the problematic behavior never existed in any released kernel, > CVE-2022-50455 cannot be valid. > > Please consider rejecting this CVE. Makes sense, I'll go reject this now, thanks for the review! greg k-h ^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2025-10-10 15:30 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
[not found] <2025100118-CVE-2022-50455-24fb@gregkh>
2025-10-10 2:19 ` CVE-2022-50455: nfs: fix possible null-ptr-deref when parsing param Wang Zhaolong
2025-10-10 15:30 ` Greg Kroah-Hartman
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®