From: Paulo Alcantara <pc@manguebit.org>
To: Diego Oliva <diego@bynar.io>, Namjae Jeon <linkinjeon@kernel.org>
Cc: Ronnie Sahlberg <ronniesahlberg@gmail.com>,
Shyam Prasad N <sprasad@microsoft.com>,
Tom Talpey <tom@talpey.com>, Bharath SM <bharathsm@microsoft.com>,
linux-cifs@vger.kernel.org, samba-technical@lists.samba.org,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH v3 0/2] smb: client: fix out-of-bounds reads in CIFSSMBRead()
Date: Wed, 02 Sep 2026 15:30:18 -0300 [thread overview]
Message-ID: <e2ec5a5c07bcd549fc9b6a595bcfab31@manguebit.org> (raw)
In-Reply-To: <20260902104207.1820332-1-diego@bynar.io>
Diego Oliva <diego@bynar.io> writes:
> CIFSSMBRead() parses the server's READ_RSP without validating either
> the length of the response or the DataOffset it carries. A malicious
> or compromised SMB1 server can exploit either to read past the end of
> the receive buffer, leaking adjacent kernel heap into the caller's
> read buffer or oopsing on unmapped memory. SMB1 is not negotiated by
> default; reaching this code requires an explicit vers=1.0 mount.
>
> Patch 1 rejects responses too short to contain a whole READ_RSP, so
> the header fields can be dereferenced safely. Patch 2 ejects a
> DataOffset/DataLength pair that falls outside the received response.
> ....
Applied.
next prev parent reply other threads:[~2026-09-02 18:30 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-02 10:42 [PATCH v3 0/2] smb: client: fix out-of-bounds reads in CIFSSMBRead() Diego Oliva
2026-09-02 10:42 ` [PATCH v3 1/2] smb: client: reject short READ responses " Diego Oliva
2026-09-02 10:42 ` [PATCH v3 2/2] smb: client: reject out-of-bounds DataOffset " Diego Oliva
2026-09-02 18:30 ` Paulo Alcantara [this message]
2026-09-02 21:29 ` [PATCH v3 0/2] smb: client: fix out-of-bounds reads " Frank Sorenson
2026-09-02 22:32 ` Paulo Alcantara
2026-09-02 23:20 ` Diego Oliva
2026-09-03 15:24 ` Paulo Alcantara
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=e2ec5a5c07bcd549fc9b6a595bcfab31@manguebit.org \
--to=pc@manguebit.org \
--cc=bharathsm@microsoft.com \
--cc=diego@bynar.io \
--cc=linkinjeon@kernel.org \
--cc=linux-cifs@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=ronniesahlberg@gmail.com \
--cc=samba-technical@lists.samba.org \
--cc=sprasad@microsoft.com \
--cc=tom@talpey.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.