From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C81D01E5B9A; Wed, 30 Sep 2026 16:46:15 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790786777; cv=none; b=t5+D4EnusZ52T6UYiLlqDa0/vQpRCAYitev4eRlVCaP7ZHFMaUK9Y/EkRx52MoNQLy3qTZgMQAMdOnIFcN9s7VswDWBFujBQy0vIrtx2snEutZE/7X0Kt8I9WotX7DA0bvsKbpCMC2FGWOS8lKq6V6n9RUsEvayHEw/x2FKZ5xQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790786777; c=relaxed/simple; bh=vayP+/vQAptDYrINzmSAQ9bfDDjWT6TbLkaWX6HipGQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Dv0CJceHQHtIDKj1jm2Ta1vcjxWuTgAmb8Tz1aNRsk9OYFCqbQKtKaAJxzoK7bs5X9TyXTovMA1TnkFgJHkL0dqon4w112qSbjIV6TL65xmQCde2BFI+qj6EaK4BZAl2SrFMZ/TCrwd5LTL1EVU25Qk8fstCYvR5nXp/pfjzAWg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=oFsmGRQO; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="oFsmGRQO" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 3058D1F000FF; Wed, 30 Sep 2026 16:46:15 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790786775; bh=8Nd9IMUTpnUW4Uxr1UG7yx0Bo6ovCWOUumJG5I/RxIA=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=oFsmGRQOHyfPgfhL2MWJrRepPG8XCg6z4/Ahipv+v99BVR48vjf6FDj3KEMGGBWTw tP1DjnvgbIuHq2TauBFPiUelTlH1ebCx/htgBsPg83jFvGDnaE5G6Afq7x2ZS+Shjy dogCeTkcjUD1+WnrcfxmMDb9ZKXk+isdsy87gNkg= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Vega , Luxing Yin , Zihan Xi , Frank Sorenson , Paulo Alcantara Subject: [PATCH 6.1 974/982] smb: client: validate POSIX create context length Date: Wed, 30 Sep 2026 17:28:30 +0200 Message-ID: <20260930152437.665236120@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152416.775402466@linuxfoundation.org> References: <20260930152416.775402466@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.1-stable review patch. If anyone has any objections, please let me know. ------------------ From: Zihan Xi commit fa2e9900dd2a3f5a1e7ef5a8c5e8d435feedbfcc upstream. parse_posix_ctxt() reads the fixed nlink, reparse_tag, and mode fields before checking that the POSIX create context contains them. A short context can pass the generic checks and still make these fixed-width reads run past its declared data. The current in-tree smb2_open_file() path passes a NULL posix pointer, so this handler is not reached on the ordinary open path. Still require the POSIX data to cover all three fields before reading them because the helper performs those unguarded reads. Keep the existing soft-failure behavior so malformed optional metadata does not fail the open. Fixes: 69dda3059e7a ("cifs: add SMB2_open() arg to return POSIX data") Cc: stable@vger.kernel.org Reported-by: Vega Assisted-by: LLM Co-developed-by: Luxing Yin Signed-off-by: Luxing Yin Signed-off-by: Zihan Xi Tested-by: Frank Sorenson Signed-off-by: Paulo Alcantara Signed-off-by: Greg Kroah-Hartman --- fs/smb/client/smb2pdu.c | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) --- a/fs/smb/client/smb2pdu.c +++ b/fs/smb/client/smb2pdu.c @@ -2190,12 +2190,15 @@ static void parse_posix_ctxt(struct create_context *cc, struct smb2_file_all_info *info, struct create_posix_rsp *posix) { - int sid_len; u8 *beg = (u8 *)cc + le16_to_cpu(cc->DataOffset); - u8 *end = beg + le32_to_cpu(cc->DataLength); + u32 dlen = le32_to_cpu(cc->DataLength); + u8 *end = beg + dlen; + int sid_len; u8 *sid; memset(posix, 0, sizeof(*posix)); + if (dlen < 3 * sizeof(__le32)) + return; posix->nlink = get_unaligned_le32(beg); posix->reparse_tag = get_unaligned_le32(beg + 4);