From: Sasha Levin <sashal@kernel.org>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: Namjae Jeon <linkinjeon@kernel.org>,
zdi-disclosures@trendmicro.com,
Steve French <stfrench@microsoft.com>,
Sasha Levin <sashal@kernel.org>,
sfrench@samba.org, linux-cifs@vger.kernel.org
Subject: [PATCH AUTOSEL 6.4 12/54] ksmbd: validate session id and tree id in compound request
Date: Sun, 13 Aug 2023 11:48:51 -0400 [thread overview]
Message-ID: <20230813154934.1067569-12-sashal@kernel.org> (raw)
In-Reply-To: <20230813154934.1067569-1-sashal@kernel.org>
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit 3df0411e132ee74a87aa13142dfd2b190275332e ]
`smb2_get_msg()` in smb2_get_ksmbd_tcon() and smb2_check_user_session()
will always return the first request smb2 header in a compound request.
if `SMB2_TREE_CONNECT_HE` is the first command in compound request, will
return 0, i.e. The tree id check is skipped.
This patch use ksmbd_req_buf_next() to get current command in compound.
Reported-by: zdi-disclosures@trendmicro.com # ZDI-CAN-21506
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/server/smb2pdu.c | 12 ++++++------
1 file changed, 6 insertions(+), 6 deletions(-)
diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c
index bd3da6cc6a98e..f4421d4bff0f8 100644
--- a/fs/smb/server/smb2pdu.c
+++ b/fs/smb/server/smb2pdu.c
@@ -87,9 +87,9 @@ struct channel *lookup_chann_list(struct ksmbd_session *sess, struct ksmbd_conn
*/
int smb2_get_ksmbd_tcon(struct ksmbd_work *work)
{
- struct smb2_hdr *req_hdr = smb2_get_msg(work->request_buf);
+ struct smb2_hdr *req_hdr = ksmbd_req_buf_next(work);
unsigned int cmd = le16_to_cpu(req_hdr->Command);
- int tree_id;
+ unsigned int tree_id;
if (cmd == SMB2_TREE_CONNECT_HE ||
cmd == SMB2_CANCEL_HE ||
@@ -114,7 +114,7 @@ int smb2_get_ksmbd_tcon(struct ksmbd_work *work)
pr_err("The first operation in the compound does not have tcon\n");
return -EINVAL;
}
- if (work->tcon->id != tree_id) {
+ if (tree_id != UINT_MAX && work->tcon->id != tree_id) {
pr_err("tree id(%u) is different with id(%u) in first operation\n",
tree_id, work->tcon->id);
return -EINVAL;
@@ -559,9 +559,9 @@ int smb2_allocate_rsp_buf(struct ksmbd_work *work)
*/
int smb2_check_user_session(struct ksmbd_work *work)
{
- struct smb2_hdr *req_hdr = smb2_get_msg(work->request_buf);
+ struct smb2_hdr *req_hdr = ksmbd_req_buf_next(work);
struct ksmbd_conn *conn = work->conn;
- unsigned int cmd = conn->ops->get_cmd_val(work);
+ unsigned int cmd = le16_to_cpu(req_hdr->Command);
unsigned long long sess_id;
/*
@@ -587,7 +587,7 @@ int smb2_check_user_session(struct ksmbd_work *work)
pr_err("The first operation in the compound does not have sess\n");
return -EINVAL;
}
- if (work->sess->id != sess_id) {
+ if (sess_id != ULLONG_MAX && work->sess->id != sess_id) {
pr_err("session id(%llu) is different with the first operation(%lld)\n",
sess_id, work->sess->id);
return -EINVAL;
--
2.40.1
next prev parent reply other threads:[~2023-08-13 15:50 UTC|newest]
Thread overview: 70+ messages / expand[flat|nested] mbox.gz Atom feed top
2023-08-13 15:48 [PATCH AUTOSEL 6.4 01/54] ksmbd: Fix unsigned expression compared with zero Sasha Levin
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 02/54] phy: qcom-snps-femto-v2: keep cfg_ahb_clk enabled during runtime suspend Sasha Levin
2023-08-13 15:48 ` Sasha Levin
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 03/54] phy: qcom-snps-femto-v2: use qcom_snps_hsphy_suspend/resume error code Sasha Levin
2023-08-13 15:48 ` Sasha Levin
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 04/54] media: amphion: use dev_err_probe Sasha Levin
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 05/54] media: imx-jpeg: Support to assign slot for encoder/decoder Sasha Levin
2023-08-13 15:48 ` Sasha Levin
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 06/54] media: pulse8-cec: handle possible ping error Sasha Levin
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 07/54] media: pci: cx23885: fix error handling for cx23885 ATSC boards Sasha Levin
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 08/54] platform/x86: serial-multi-instantiate: Auto detect IRQ resource for CSC3551 Sasha Levin
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 09/54] 9p: virtio: fix unlikely null pointer deref in handle_rerror Sasha Levin
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 10/54] 9p: virtio: make sure 'offs' is initialized in zc_request Sasha Levin
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 11/54] ksmbd: fix out of bounds in smb3_decrypt_req() Sasha Levin
2023-08-13 15:48 ` Sasha Levin [this message]
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 13/54] ksmbd: no response from compound read Sasha Levin
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 14/54] ksmbd: fix out of bounds in init_smb2_rsp_hdr() Sasha Levin
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 15/54] ASoC: da7219: Flush pending AAD IRQ when suspending Sasha Levin
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 16/54] ASoC: da7219: Check for failure reading AAD IRQ events Sasha Levin
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 17/54] ASoC: nau8821: Add DMI quirk mechanism for active-high jack-detect Sasha Levin
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 18/54] thermal: core: constify params in thermal_zone_device_register Sasha Levin
2023-08-22 10:43 ` Pavel Machek
2023-08-22 11:31 ` Greg KH
2023-09-05 6:03 ` Ahmad Fatoum
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 19/54] net: hns3: add tm flush when setting tm Sasha Levin
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 20/54] ethernet: atheros: fix return value check in atl1c_tso_csum() Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 21/54] vxlan: generalize vxlan_parse_gpe_hdr and remove unused args Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 22/54] m68k: Fix invalid .section syntax Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 23/54] btrfs: remove BUG_ON()'s in add_new_free_space() Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 24/54] s390/dasd: use correct number of retries for ERP requests Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 25/54] s390/dasd: fix hanging device after request requeue Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 26/54] fs/nls: make load_nls() take a const parameter Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 27/54] cifs: fix charset issue in reconnection Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 28/54] ASoC: rt5682-sdw: fix for JD event handling in ClockStop Mode0 Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 29/54] ASoc: codecs: ES8316: Fix DMIC config Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 30/54] ASoC: rt712-sdca: fix for JD event handling in ClockStop Mode0 Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 31/54] ASoC: rt711: " Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 32/54] ASoC: rt711-sdca: " Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 33/54] ASoC: atmel: Fix the 8K sample parameter in I2SC master Sasha Levin
2023-08-13 15:49 ` Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 34/54] ALSA: usb-audio: Add quirk for Microsoft Modern Wireless Headset Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 35/54] platform/x86/amd/pmf: reduce verbosity of apmf_get_system_params Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 36/54] platform/x86/amd/pmf: Notify OS power slider update Sasha Levin
2023-08-22 10:44 ` Pavel Machek
2023-08-22 14:46 ` Mario Limonciello
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 37/54] platform/x86: intel: hid: Always call BTNL ACPI method Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 38/54] platform/x86/intel/hid: Add HP Dragonfly G2 to VGBS DMI quirks Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 39/54] platform/x86: think-lmi: Use kfree_sensitive instead of kfree Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 40/54] platform/x86: asus-wmi: Fix setting RGB mode on some TUF laptops Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 41/54] platform/x86: huawei-wmi: Silence ambient light sensor Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 42/54] drm/amd/smu: use AverageGfxclkFrequency* to replace previous GFX Curr Clock Sasha Levin
2023-08-13 15:49 ` Sasha Levin
2023-08-13 15:49 ` Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 43/54] drm/amd/display: Guard DCN31 PHYD32CLK logic against chip family Sasha Levin
2023-08-13 15:49 ` Sasha Levin
2023-08-13 15:49 ` Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 44/54] drm/amd/display: Exit idle optimizations before attempt to access PHY Sasha Levin
2023-08-13 15:49 ` Sasha Levin
2023-08-13 15:49 ` Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 45/54] ovl: Always reevaluate the file signature for IMA Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 46/54] ata: pata_arasan_cf: Use dev_err_probe() instead dev_err() in data_xfer() Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 47/54] rbd: make get_lock_owner_info() return a single locker or NULL Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 48/54] rbd: harden get_lock_owner_info() a bit Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 49/54] ALSA: usb-audio: Update for native DSD support quirks Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 50/54] staging: fbtft: ili9341: use macro FBTFT_REGISTER_SPI_DRIVER Sasha Levin
2023-08-13 15:49 ` Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 51/54] LoongArch: Only fiddle with CHECKFLAGS if `need-compiler' Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 52/54] LoongArch: Fix CMDLINE_EXTEND and CMDLINE_BOOTLOADER handling Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 53/54] security: keys: perform capable check only on privileged operations Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 54/54] kprobes: Prohibit probing on CFI preamble symbol Sasha Levin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20230813154934.1067569-12-sashal@kernel.org \
--to=sashal@kernel.org \
--cc=linkinjeon@kernel.org \
--cc=linux-cifs@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=sfrench@samba.org \
--cc=stable@vger.kernel.org \
--cc=stfrench@microsoft.com \
--cc=zdi-disclosures@trendmicro.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.