diff options
| author | Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr> | 2026-09-20 18:15:03 +0000 |
|---|---|---|
| committer | Namjae Jeon <linkinjeon@kernel.org> | 2026-09-24 12:38:15 +0900 |
| commit | 4ceeaa7b1a1a022ee329c4068339b3f44c1514a2 (patch) | |
| tree | 370ea5dc54c172d62bbb8d5fa7f079e712b189a7 /fs/smb/common | |
| parent | bf0333dde8db0e6db8d938b32efc3404a1028bdd (diff) | |
| download | linux-next-4ceeaa7b1a1a022ee329c4068339b3f44c1514a2.tar.gz linux-next-4ceeaa7b1a1a022ee329c4068339b3f44c1514a2.zip | |
ksmbd: fix SMB2 CREATE response buffer overflow
smb2_allocate_rsp_buf() uses the MAX_CIFS_SMALL_BUFFER_SIZE
(448-byte) buffer for a single SMB2_CREATE response. That buffer also
holds a 4-byte length field, which only leaves 444 bytes for the SMB2
body.
The AAPL response made this buffer too small. After 8f1b796ff113, a
request with AAPL response contexts may need at least 456 bytes. In
the 456-byte case, create_aapl_rsp_buf() is appended last, clears 128
bytes, and writes 12 bytes past the allocation.
KASAN reports:
BUG: KASAN: slab-out-of-bounds in create_aapl_rsp_buf+0x31/0x6e0
Write of size 128 at addr ffff88800370954c by task kworker/0:0/9
...
create_aapl_rsp_buf+0x31/0x6e0
smb2_open+0x58f9/0xef10
...
smb2_allocate_rsp_buf+0x19d/0x370
...
The buggy address is located 332 bytes inside of
allocated 448-byte region [ffff888003709400, ffff8880037095c0)
Reserve enough space for any fixed CREATE response KSMBD can build.
Store the required allocation size in the per-dialect values table.
This keeps the small buffer for other commands and avoids using the max
transaction buffer for every CREATE.
Fixes: 8f1b796ff113 ("ksmbd: add AAPL kAAPL_SERVER_QUERY create context support")
Assisted-by: Codex:gpt-5
Signed-off-by: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Diffstat (limited to 'fs/smb/common')
| -rw-r--r-- | fs/smb/common/smbglob.h | 1 |
1 files changed, 1 insertions, 0 deletions
diff --git a/fs/smb/common/smbglob.h b/fs/smb/common/smbglob.h index d9c7e6e7af29..fdf840888062 100644 --- a/fs/smb/common/smbglob.h +++ b/fs/smb/common/smbglob.h @@ -40,6 +40,7 @@ struct smb_version_values { size_t create_disk_id_size; size_t create_posix_size; size_t create_aapl_size; + size_t create_rsp_size; }; static inline unsigned int get_rfc1002_len(void *buf) |
