diff options
| author | Frank Sorenson <sorenson@redhat.com> | 2026-09-16 16:33:56 -0500 |
|---|---|---|
| committer | Paulo Alcantara <pc@manguebit.org> | 2026-09-17 15:04:03 -0300 |
| commit | 1b3221bb121079ad79a1f3c3aa360ba649832e7a (patch) | |
| tree | 51fbba82cde3ed4972940b7e1c3e66a6051affc9 /fs | |
| parent | e83330c55edc0c3ac08aa6c95e49e4694c65523b (diff) | |
| download | lwn-1b3221bb121079ad79a1f3c3aa360ba649832e7a.tar.gz lwn-1b3221bb121079ad79a1f3c3aa360ba649832e7a.zip | |
smb: client: reject short Next offsets in parse_server_interfaces()
In parse_server_interfaces(), the server-supplied Next offset is
validated against bytes_left, but not against the size of the interface
structure itself.
A small, non-zero Next value can pass the bounds check but advance the
pointer by less than sizeof(*p). This causes the next iteration of the
loop to read misaligned, overlapping structure fields.
Fix this by ensuring the Next offset is at least sizeof(*p).
Fixes: 7d34ec36abb8 ("smb3: fix for slab out of bounds on mount to ksmbd")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Reviewed-by: David Howells <dhowells@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Diffstat (limited to 'fs')
| -rw-r--r-- | fs/smb/client/smb2ops.c | 6 |
1 files changed, 3 insertions, 3 deletions
diff --git a/fs/smb/client/smb2ops.c b/fs/smb/client/smb2ops.c index 7f2177f6fc01..bda940cb3784 100644 --- a/fs/smb/client/smb2ops.c +++ b/fs/smb/client/smb2ops.c @@ -785,9 +785,9 @@ next_iface: break; } /* Validate that Next doesn't point beyond the buffer */ - if (next > bytes_left) { - cifs_dbg(VFS, "%s: invalid Next pointer %zu > %zd\n", - __func__, next, bytes_left); + if (next < sizeof(*p) || next > bytes_left) { + cifs_dbg(VFS, "%s: invalid Next pointer %zu out of range [%zu, %zd]\n", + __func__, next, sizeof(*p), bytes_left); rc = -EINVAL; goto out; } |
