-
Tyler Hicks authored
A malicious monitor can craft an auth reply message that could cause a NULL function pointer dereference in the client's kernel. To prevent this, the auth_none protocol handler needs an empty ceph_auth_client_ops->build_request() function. CVE-2013-1059 Signed-off-by:
Tyler Hicks <tyhicks@canonical.com>
Reported-by:
Chanam Park <chanam.park@hkpco.kr>
Reviewed-by:
Seth Arnold <seth.arnold@canonical.com>
Reviewed-by:
Sage Weil <sage@inktank.com>
Cc: stable@vger.kernel.org2cb33cac