From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4B7524E4306; Wed, 30 Sep 2026 16:36:43 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790786204; cv=none; b=W4NDyidNdRSJbxWDek8TzF3nubYMFCjL7FOJ7RxPWtqIM2Yq30D6Q+39YVIrg3x1NH9Z4jx+gwTHMrxQudBKu7IWzEu1amuqhaJnD8DDZ2B84KNN/2pMjQVnnJIhEh+uw5wjy74Ltj7N/drzQnvvG3wkADhaKNxHRhXNZJ3XMuw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790786204; c=relaxed/simple; bh=i0kxhS6AC17PceH0Q1V0U6QyjqyO45xeyhe/2heDRSc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=GstgGFOBtgTMgBMgr884IyeL4JxfNIrDIROwPwXlGOaDCM02/+lURLoLp7fLk2NnzpkGmNr9C9O4qCQFWR+yKhpHrGFiJCutA1OO0imuLT3tkZjOmtpXs+J7NhT+C13WIVmxtRQ+xpYOYLSBI4wdH45S9bYS7V3PhcZjHgfnHfA= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=hVydNyXM; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="hVydNyXM" Received: by smtp.kernel.org (Postfix) with ESMTPSA id A66B81F000FF; Wed, 30 Sep 2026 16:36:42 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790786203; bh=0cuiLYHjHq5Xyd1OhaFzZe6L2DmJa8yKHjEujJouFwQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=hVydNyXMz/LZITRh9wHupZ4NPa9EaeU1cO8VecyaopyRL42hN2vCtIoGLHOxqoWxK aVf/AIDUKeFCSC4fVZxanO1vvljWk014IGqraY2lV4FhF2DyNEDY9629Y2Tw/dcrKa x/BmgIRgX2FXd6LJqkD6f40CLsERC+YJ9l8Zq9Ww= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Frank Sorenson , David Howells , Paulo Alcantara Subject: [PATCH 6.1 777/982] smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs Date: Wed, 30 Sep 2026 17:25:13 +0200 Message-ID: <20260930152433.444080637@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152416.775402466@linuxfoundation.org> References: <20260930152416.775402466@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.1-stable review patch. If anyone has any objections, please let me know. ------------------ From: Frank Sorenson commit 05762c5bc1cfdcac36747994fde2c04387a457f1 upstream. Fix several related bounds checking and pointer lifecycle issues in receive_encrypted_standard()'s handling of compound encrypted frames: - Clear next_buffer after assigning it to server->bigbuf. A stale next_buffer pointer can lead to a use-after-free on subsequent error paths. - Update pdu_length to the decrypted plaintext size (buf_size). Using the pre-decryption length allows NextCommand to point into stale ciphertext residue. - Reject next_cmd values smaller than MID_HEADER_SIZE(server). - Fix an integer overflow in the upper bound check by verifying pdu_length - next_cmd < MID_HEADER_SIZE(server), ensuring the trailing slice is large enough for a header. Fixes: b24df3e30cbf ("cifs: update receive_encrypted_standard to handle compounded responses") Cc: stable@vger.kernel.org Signed-off-by: Frank Sorenson Reviewed-by: David Howells Signed-off-by: Paulo Alcantara Signed-off-by: Greg Kroah-Hartman --- fs/smb/client/smb2ops.c | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) --- a/fs/smb/client/smb2ops.c +++ b/fs/smb/client/smb2ops.c @@ -5205,6 +5205,7 @@ receive_encrypted_standard(struct TCP_Se length = decrypt_raw_data(server, buf, buf_size, NULL, 0, 0, false); if (length) return length; + pdu_length = buf_size; next_is_large = server->large_buf; one_more: @@ -5217,8 +5218,15 @@ one_more: } if (next_cmd) { - if (WARN_ON_ONCE(next_cmd > pdu_length)) + if (next_cmd < MID_HEADER_SIZE(server) || + next_cmd > pdu_length || + pdu_length - next_cmd < MID_HEADER_SIZE(server)) { + unsigned int max_next = pdu_length > (unsigned int)MID_HEADER_SIZE(server) ? + pdu_length - (unsigned int)MID_HEADER_SIZE(server) : 0; + cifs_server_dbg(VFS, "invalid NextCommand offset %u out of range [%zu, %u]\n", + next_cmd, MID_HEADER_SIZE(server), max_next); return -1; + } if (next_is_large) next_buffer = (char *)cifs_buf_get(); else @@ -5254,6 +5262,7 @@ one_more: server->bigbuf = buf = next_buffer; else server->smallbuf = buf = next_buffer; + next_buffer = NULL; goto one_more; } else if (ret != 0) { /*