summaryrefslogtreecommitdiff
path: root/fs/smb/common
diff options
context:
space:
mode:
authorJérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>2026-09-20 18:15:03 +0000
committerNamjae Jeon <linkinjeon@kernel.org>2026-09-24 12:38:15 +0900
commit4ceeaa7b1a1a022ee329c4068339b3f44c1514a2 (patch)
tree370ea5dc54c172d62bbb8d5fa7f079e712b189a7 /fs/smb/common
parentbf0333dde8db0e6db8d938b32efc3404a1028bdd (diff)
downloadlinux-next-4ceeaa7b1a1a022ee329c4068339b3f44c1514a2.tar.gz
linux-next-4ceeaa7b1a1a022ee329c4068339b3f44c1514a2.zip
ksmbd: fix SMB2 CREATE response buffer overflow
smb2_allocate_rsp_buf() uses the MAX_CIFS_SMALL_BUFFER_SIZE (448-byte) buffer for a single SMB2_CREATE response. That buffer also holds a 4-byte length field, which only leaves 444 bytes for the SMB2 body. The AAPL response made this buffer too small. After 8f1b796ff113, a request with AAPL response contexts may need at least 456 bytes. In the 456-byte case, create_aapl_rsp_buf() is appended last, clears 128 bytes, and writes 12 bytes past the allocation. KASAN reports: BUG: KASAN: slab-out-of-bounds in create_aapl_rsp_buf+0x31/0x6e0 Write of size 128 at addr ffff88800370954c by task kworker/0:0/9 ... create_aapl_rsp_buf+0x31/0x6e0 smb2_open+0x58f9/0xef10 ... smb2_allocate_rsp_buf+0x19d/0x370 ... The buggy address is located 332 bytes inside of allocated 448-byte region [ffff888003709400, ffff8880037095c0) Reserve enough space for any fixed CREATE response KSMBD can build. Store the required allocation size in the per-dialect values table. This keeps the small buffer for other commands and avoids using the max transaction buffer for every CREATE. Fixes: 8f1b796ff113 ("ksmbd: add AAPL kAAPL_SERVER_QUERY create context support") Assisted-by: Codex:gpt-5 Signed-off-by: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr> Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Diffstat (limited to 'fs/smb/common')
-rw-r--r--fs/smb/common/smbglob.h1
1 files changed, 1 insertions, 0 deletions
diff --git a/fs/smb/common/smbglob.h b/fs/smb/common/smbglob.h
index d9c7e6e7af29..fdf840888062 100644
--- a/fs/smb/common/smbglob.h
+++ b/fs/smb/common/smbglob.h
@@ -40,6 +40,7 @@ struct smb_version_values {
size_t create_disk_id_size;
size_t create_posix_size;
size_t create_aapl_size;
+ size_t create_rsp_size;
};
static inline unsigned int get_rfc1002_len(void *buf)