summaryrefslogtreecommitdiff
path: root/fs
diff options
context:
space:
mode:
authorFrank Sorenson <sorenson@redhat.com>2026-09-16 16:33:56 -0500
committerPaulo Alcantara <pc@manguebit.org>2026-09-17 15:04:03 -0300
commit1b3221bb121079ad79a1f3c3aa360ba649832e7a (patch)
tree51fbba82cde3ed4972940b7e1c3e66a6051affc9 /fs
parente83330c55edc0c3ac08aa6c95e49e4694c65523b (diff)
downloadlwn-1b3221bb121079ad79a1f3c3aa360ba649832e7a.tar.gz
lwn-1b3221bb121079ad79a1f3c3aa360ba649832e7a.zip
smb: client: reject short Next offsets in parse_server_interfaces()
In parse_server_interfaces(), the server-supplied Next offset is validated against bytes_left, but not against the size of the interface structure itself. A small, non-zero Next value can pass the bounds check but advance the pointer by less than sizeof(*p). This causes the next iteration of the loop to read misaligned, overlapping structure fields. Fix this by ensuring the Next offset is at least sizeof(*p). Fixes: 7d34ec36abb8 ("smb3: fix for slab out of bounds on mount to ksmbd") Cc: stable@vger.kernel.org Signed-off-by: Frank Sorenson <sorenson@redhat.com> Reviewed-by: David Howells <dhowells@redhat.com> Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Diffstat (limited to 'fs')
-rw-r--r--fs/smb/client/smb2ops.c6
1 files changed, 3 insertions, 3 deletions
diff --git a/fs/smb/client/smb2ops.c b/fs/smb/client/smb2ops.c
index 7f2177f6fc01..bda940cb3784 100644
--- a/fs/smb/client/smb2ops.c
+++ b/fs/smb/client/smb2ops.c
@@ -785,9 +785,9 @@ next_iface:
break;
}
/* Validate that Next doesn't point beyond the buffer */
- if (next > bytes_left) {
- cifs_dbg(VFS, "%s: invalid Next pointer %zu > %zd\n",
- __func__, next, bytes_left);
+ if (next < sizeof(*p) || next > bytes_left) {
+ cifs_dbg(VFS, "%s: invalid Next pointer %zu out of range [%zu, %zd]\n",
+ __func__, next, sizeof(*p), bytes_left);
rc = -EINVAL;
goto out;
}