-
Tyler Hicks authored
A malicious monitor can craft an auth reply message that could cause a NULL function pointer dereference in the client's kernel. To prevent this, the auth_none protocol handler needs an empty ceph_auth_client_ops->build_request() function. CVE-2013-1059 Signed-off-by:
Tyler Hicks <tyhicks@canonical.com> Reported-by:
Chanam Park <chanam.park@hkpco.kr> Reviewed-by:
Seth Arnold <seth.arnold@canonical.com> Reviewed-by:
Sage Weil <sage@inktank.com> Cc: stable@vger.kernel.org
2cb33cac