All of lore.kernel.org
 help / color / mirror / Atom feed
From: Frank Sorenson <sorenson@redhat.com>
To: linux-cifs@vger.kernel.org, pc@manguebit.org
Cc: linkinjeon@kernel.org, ronniesahlberg@gmail.com,
	sprasad@microsoft.com, tom@talpey.com, bharathsm@microsoft.com
Subject: [PATCH v4 00/10] smb: client: fix OOB reads and UAFs in SMB2/3 receive paths
Date: Sun, 13 Sep 2026 16:44:58 -0500	[thread overview]
Message-ID: <20260913214510.3071370-1-sorenson@redhat.com> (raw)

This series fixes ten bounds-checking defects in the SMB2/3 client,
all of which are reachable from a malicious or compromised server.

Patches 1-3 address the compound encrypted frame processing path:

Patch 1 fixes multiple pointer lifecycle and bounds-checking issues
in receive_encrypted_standard(), including a stale next_buffer pointer
that causes a UAF on error paths, and an integer overflow that allows
malformed trailing slices to bypass length checks.

Patch 2 adds a table of per-command minimum-response struct sizes,
used to reject responses too short for smb2_get_data_area_len() to
safely read command-specific struct fields.

Patch 3 fixes server->total_read tracking so that smb2_check_message()
validates against the actual per-sub-PDU size, rather than the full
remaining compound tail. Without this, a truncated non-last sub-PDU
could bypass the guards added in patch 2.

Note for stable: although patch 3 carries a Fixes: tag and Cc: stable,
I am not sure whether patch 2 should, since it adds a new table rather
than being a true fix. They are complementary: patch 3 supplies the
correct per-sub-PDU length that patch 2's guard consumes. Patch 3 is
safe on its own, but its computed length will not be checked against
the per-command minimum unless patch 2 is included as well.

The remaining patches fix lower-bound gaps and OOB reads in DFS referral
parsing, server interface list traversal, EA list traversal, posix SID
bounds, change-notify offset, snapshot enumeration, and SMB1 reparse
point validation.

The create-context patch carried through v3 as patch 11 has been dropped
from this series. Zihan Xi's recent series:

  [PATCH v3 0/2] smb: client: fix create context out-of-bounds reads
  https://lore.kernel.org/r/cover.1788516372.git.zihanx@nebusec.ai

covers the same defects, arrives with a PoC, and fixes
parse_query_id_ctxt() in a better way. Rather than post two
overlapping/competing fixes, I will help with reviewing and improving
that series instead. If it stalls, I'll re-post my version.

Testing compared cifs-next (7.2+) with and without this patchset:

samba - v3.1.1, v3.1.1+sign, v3.1.1+seal, v2.1, v2.1+sign, v1:
  - no new failures attributable to this series.
  - found netfs bug causing generic/759 with signing to fail
    (resolved by David Howells--now succeeds).

Windows Server 2022 - v3.1.1, v3.1.1+sign, v3.1.1+seal,
  v3.1.1+multichannel:
  - no failures.

v4 changes:
 - patch 2: dropped the smb2_check_min_pdu_len_table() BUILD_BUG_ON helper.
 - dropped patch 11 ("smb: client: fix OOB reads in smb2_parse_contexts()")
   in favor of Zihan Xi's series, as described above.
 - patch 9: corrected a bogus Fixes: tag. Explained bound choice of
   sizeof(struct smb_snapshot_array) vs the 16-byte MIN_SNAPSHOT_ARRAY_SIZE
   of MS-SMB2 3.3.5.15.1.
 - testing details
 - commit subjects and messages tightened throughout.

v3 changes:
 https://lore.kernel.org/linux-cifs/20260826153147.4112943-1-sorenson@redhat.com
 - respin entire series

v2 changes:
 - patch 6: reject next_entry_offset values that leave fewer than
   sizeof(*src) bytes remaining after advancing.

Frank Sorenson (10):
  smb: client: fix next_buffer UAF and NextCommand bounds in compound
    PDUs
  smb: client: validate minimum PDU size before smb2_get_data_area_len()
  smb: client: fix server->total_read for compound encrypted PDUs
  smb: client: fix missing lower-bound check on DFS referral string
    offsets
  smb: client: reject short Next offsets in parse_server_interfaces()
  smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs()
  smb: client: fix missing iov bounds check in parse_posix_sids()
  smb: client: fix underflow in is_valid_oplock_break() notify offset
    check
  smb: client: fix potential OOB read in smb3_enum_snapshots()
  smb: client: fix reparse buffer bounds in cifs_query_reparse_point()

 fs/smb/client/cifssmb.c   |  2 +-
 fs/smb/client/misc.c      | 12 +++++++--
 fs/smb/client/smb1misc.c  |  3 ++-
 fs/smb/client/smb2inode.c | 11 +++++++++
 fs/smb/client/smb2misc.c  | 40 ++++++++++++++++++++++++++++++
 fs/smb/client/smb2ops.c   | 51 +++++++++++++++++++++++++++++----------
 fs/smb/client/trace.h     |  1 +
 7 files changed, 103 insertions(+), 17 deletions(-)

-- 
2.55.0


             reply	other threads:[~2026-09-13 21:45 UTC|newest]

Thread overview: 17+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-13 21:44 Frank Sorenson [this message]
2026-09-13 21:44 ` [PATCH v4 01/10] smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs Frank Sorenson
2026-09-13 21:45 ` [PATCH v4 02/10] smb: client: validate minimum PDU size before smb2_get_data_area_len() Frank Sorenson
2026-09-15 15:04   ` Paulo Alcantara
2026-09-15 16:41     ` Frank Sorenson
2026-09-16 14:22       ` Paulo Alcantara
2026-09-16 19:55         ` Frank Sorenson
2026-09-13 21:45 ` [PATCH v4 03/10] smb: client: fix server->total_read for compound encrypted PDUs Frank Sorenson
2026-09-13 21:45 ` [PATCH v4 04/10] smb: client: fix missing lower-bound check on DFS referral string offsets Frank Sorenson
2026-09-13 21:45 ` [PATCH v4 05/10] smb: client: reject short Next offsets in parse_server_interfaces() Frank Sorenson
2026-09-13 21:45 ` [PATCH v4 06/10] smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs() Frank Sorenson
2026-09-13 21:45 ` [PATCH v4 07/10] smb: client: fix missing iov bounds check in parse_posix_sids() Frank Sorenson
2026-09-13 21:45 ` [PATCH v4 08/10] smb: client: fix underflow in is_valid_oplock_break() notify offset check Frank Sorenson
2026-09-13 21:45 ` [PATCH v4 09/10] smb: client: fix potential OOB read in smb3_enum_snapshots() Frank Sorenson
2026-09-13 21:45 ` [PATCH v4 10/10] smb: client: fix reparse buffer bounds in cifs_query_reparse_point() Frank Sorenson
2026-09-14  1:08 ` [PATCH v4 00/10] smb: client: fix OOB reads and UAFs in SMB2/3 receive paths Frank Sorenson
2026-09-15 15:50   ` Paulo Alcantara

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260913214510.3071370-1-sorenson@redhat.com \
    --to=sorenson@redhat.com \
    --cc=bharathsm@microsoft.com \
    --cc=linkinjeon@kernel.org \
    --cc=linux-cifs@vger.kernel.org \
    --cc=pc@manguebit.org \
    --cc=ronniesahlberg@gmail.com \
    --cc=sprasad@microsoft.com \
    --cc=tom@talpey.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.