Skip to content

Add README.security-scan documenting the 2026-05 security review#588

Open
vmihalis wants to merge 1 commit into
sahlberg:masterfrom
vmihalis:security-scan-doc
Open

Add README.security-scan documenting the 2026-05 security review#588
vmihalis wants to merge 1 commit into
sahlberg:masterfrom
vmihalis:security-scan-doc

Conversation

@vmihalis
Copy link
Copy Markdown

@vmihalis vmihalis commented Jun 1, 2026

Hi Ronnie — as offered, here's the README.security-scan writeup for the five issues from my 2026-05-20 report. Thanks again for fixing them all and adding the Reported-by: credits.

The file covers the methodology, the five findings (file:line + CWE), the severity scoring, the threat model, and remediation status, linking each fix commit:

  • F-1 HIGH (CWE-125) — libnfs_zdr_bytes signed cast → OOB R/W — 3c23b77
  • F-2 HIGH (CWE-125) — NFSv4 negative slen → loop + OOB read — 0a62821
  • F-3 HIGH (CWE-476) — zdr_malloc overflow → NULL deref — 627e37d
  • F-4 MED (CWE-674) — READDIR unbounded recursion → stack overflow — 0e63985
  • F-5 MED (CWE-297) — silent mTLS downgrade — f0b109d

Kept factual/technical. Happy to adjust wording or restructure however you'd like before merge, and I'll add CVE IDs once assigned. Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant