#VU108514 Input validation error in OpenBSD
Published: May 5, 2025
OpenBSD
OpenBSD
Description
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input within the nfsrv_readdir() and nfsrv_readdirplus() functions in sys/nfs/nfs_serv.c in nfsd(8). A remote user can send a specially crafted NFS request to the server and perform a denial of service (DoS) attack.