summaryrefslogtreecommitdiff
path: root/fs
diff options
context:
space:
mode:
authorFrank Sorenson <sorenson@redhat.com>2026-09-16 16:34:00 -0500
committerPaulo Alcantara <pc@manguebit.org>2026-09-17 15:04:26 -0300
commit5f0306e731e2f46e91419eae57eee3a241c055e0 (patch)
tree62625befaa583caf0bd6aaed2344182ee9757a71 /fs
parent4775c3b7a597907e0b97556c7986fda238a377ae (diff)
downloadlwn-5f0306e731e2f46e91419eae57eee3a241c055e0.tar.gz
lwn-5f0306e731e2f46e91419eae57eee3a241c055e0.zip
smb: client: fix reparse buffer bounds in cifs_query_reparse_point()
In cifs_query_reparse_point(), the start >= end check before casting to struct reparse_data_buffer * only ensures the start pointer is within the response. It fails to verify that there is enough space remaining for the fixed 8-byte header of the structure. If a server provides a DataOffset that leaves less than 8 bytes remaining, the check passes, but subsequent reads of ReparseTag and ReparseDataLength will occur out-of-bounds. Fix this by ensuring the remaining space is at least the size of the reparse_data_buffer structure before accessing its fields. Fixes: 56e84c64fc25 ("cifs: Fix validation of SMB1 query reparse point response") Cc: stable@vger.kernel.org Signed-off-by: Frank Sorenson <sorenson@redhat.com> Reviewed-by: David Howells <dhowells@redhat.com> Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Diffstat (limited to 'fs')
-rw-r--r--fs/smb/client/cifssmb.c2
1 files changed, 1 insertions, 1 deletions
diff --git a/fs/smb/client/cifssmb.c b/fs/smb/client/cifssmb.c
index f9aff0712794..6dddbd84b93b 100644
--- a/fs/smb/client/cifssmb.c
+++ b/fs/smb/client/cifssmb.c
@@ -3080,7 +3080,7 @@ int cifs_query_reparse_point(const unsigned int xid,
end = 2 + get_bcc(&io_rsp->hdr) + (__u8 *)&io_rsp->ByteCount;
start = (__u8 *)&io_rsp->hdr.Protocol + data_offset;
- if (start >= end) {
+ if (start >= end || (size_t)(end - start) < sizeof(*buf)) {
rc = smb_EIO2(smb_eio_trace_qreparse_data_area,
(unsigned long)start - (unsigned long)io_rsp,
(unsigned long)end - (unsigned long)io_rsp);