From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B0997502560; Wed, 30 Sep 2026 17:21:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790788881; cv=none; b=aVBZjIh125eX01L2YNN7ZVtkJOBqJD+x5k2iKAbxQyaMIlFk0ovxnWnYkIDyqB84D7CqtXwFtkTcPyY028bL/5LlB70yHYF4YKAT73Jc4oiVkN6Y+8149pTrn4EXGmUjXTaxC+mD2XZmIrgAcpR9VV00Gyn5xXNkGJN1oLzVQB4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790788881; c=relaxed/simple; bh=rhdAe/zOYUaWS1ovGEWKL1fXFxH3KZdo0IfS2ieUrL0=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=YHRirkqBEsCCbCowh98j0oh+k3jXYziIrlSeoDtuJ+mjOxv3oAAPCQEfZ7GdKA6t3AW6wnPEDPg5DuRxgq5hMVUp3QKIQKrKX9BtDAcCxFKXvRuv1yqJgzb+aJDaBmhkAkgLjGtdNISJD2mnKpETa9y3ugr9HThoUyjrDIfnqXw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=pplCfpxH; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="pplCfpxH" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 167A61F00898; Wed, 30 Sep 2026 17:21:19 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790788880; bh=wBboBP0rtFrIUXzMOsAfYfUN9JXYIeRCdhFRzBQEjMs=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=pplCfpxH1TzrmTCdC5DZluCodGmJPnLlJw7M1Fk6Lp8szvuLnMvZwbQunTLrUaJSH l6tqSxPzOkyoIW8SKTOSpGniMACzv8Ch79gizN5Qha/gc427ICWdiI7uF4XwAhGHRO 1286Upb5ofrkppS9nb+XaBkx7iVwn6cWGdT+cYMo= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Frank Sorenson , David Howells , Paulo Alcantara Subject: [PATCH 6.12 281/877] smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs Date: Wed, 30 Sep 2026 17:19:52 +0200 Message-ID: <20260930152420.781516600@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152414.738996857@linuxfoundation.org> References: <20260930152414.738996857@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.12-stable review patch. If anyone has any objections, please let me know. ------------------ From: Frank Sorenson commit 05762c5bc1cfdcac36747994fde2c04387a457f1 upstream. Fix several related bounds checking and pointer lifecycle issues in receive_encrypted_standard()'s handling of compound encrypted frames: - Clear next_buffer after assigning it to server->bigbuf. A stale next_buffer pointer can lead to a use-after-free on subsequent error paths. - Update pdu_length to the decrypted plaintext size (buf_size). Using the pre-decryption length allows NextCommand to point into stale ciphertext residue. - Reject next_cmd values smaller than MID_HEADER_SIZE(server). - Fix an integer overflow in the upper bound check by verifying pdu_length - next_cmd < MID_HEADER_SIZE(server), ensuring the trailing slice is large enough for a header. Fixes: b24df3e30cbf ("cifs: update receive_encrypted_standard to handle compounded responses") Cc: stable@vger.kernel.org Signed-off-by: Frank Sorenson Reviewed-by: David Howells Signed-off-by: Paulo Alcantara Signed-off-by: Greg Kroah-Hartman --- fs/smb/client/smb2ops.c | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) --- a/fs/smb/client/smb2ops.c +++ b/fs/smb/client/smb2ops.c @@ -5237,6 +5237,7 @@ receive_encrypted_standard(struct TCP_Se length = decrypt_raw_data(server, buf, buf_size, NULL, false); if (length) return length; + pdu_length = buf_size; next_is_large = server->large_buf; one_more: @@ -5249,8 +5250,15 @@ one_more: } if (next_cmd) { - if (WARN_ON_ONCE(next_cmd > pdu_length)) + if (next_cmd < MID_HEADER_SIZE(server) || + next_cmd > pdu_length || + pdu_length - next_cmd < MID_HEADER_SIZE(server)) { + unsigned int max_next = pdu_length > (unsigned int)MID_HEADER_SIZE(server) ? + pdu_length - (unsigned int)MID_HEADER_SIZE(server) : 0; + cifs_server_dbg(VFS, "invalid NextCommand offset %u out of range [%zu, %u]\n", + next_cmd, MID_HEADER_SIZE(server), max_next); return -1; + } if (next_is_large) next_buffer = (char *)cifs_buf_get(); else @@ -5286,6 +5294,7 @@ one_more: server->bigbuf = buf = next_buffer; else server->smallbuf = buf = next_buffer; + next_buffer = NULL; goto one_more; } else if (ret != 0) { /*