Red Hat Bugzilla – Bug 1540439
CVE-2018-1000028 kernel: Improper sorting of GIDs in nfsd can lead to incorrect permissions being applied
Last modified: 2018-08-28 18:33:38 EDT
nfsd in the Linux kernel 4.15, does not properly sort gids when rootsquash is enabled. The groups_sort() function is called inside a loop that copies/squashes gids. he net result is that the highest numbered valid gids are replaced with any lower-valued garbage gids, possibly including 0. This can corrupt group membership, leading to permission denials for the client. Upstream Patch: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=1995266727fa8143897e89b55f5d3c79aa828420