A bad Ceph storage server could make the client kernel read past a reply
Brief
The commits name a multi-tenant cloud OSD as the attacker.
Notes
437b6551cfcc235eea1d735a874f9d421f555e17 (Pavitra Jha). A short lock-info reply can make the client read past the buffer. Fixes: d4ed4a530562. Cc: stable.
00ead17c7de137a692edee59f2772e6af687e8eb (same author). A zero-length watcher-list reply then a bare 32-bit read; the garbage count goes to the allocator. Fixes: a4ed38d7a180. Cc: stable.
3660b98d1204b419f6a77e9a295f148dcf38d042 (Raphael Zimmer). A corrupted osdmap can carry an OSD index that does not exist; the client then indexes state arrays with it. Fixes: 5e8d4d36bf23. Cc: stable.
Landed via c5890ac6d55c3d13e2d17817fec6676941ef08ee (ceph-for-7.2-rc8). No linux-cve-announce. Session already exists; this is not a public-internet packet. Do not invent a CVE.
Commit 437b6551cfcc235eea1d735a874f9d421f555e17; 00ead17c7de137a692edee59f2772e6af687e8eb; 3660b98d1204b419f6a77e9a295f148dcf38d042