From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx1.manguebit.org (mx1.manguebit.org [143.255.12.172]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 91E66382397; Sun, 6 Sep 2026 18:15:43 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=143.255.12.172 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788718545; cv=none; b=gc/TLjVlfv87N9alHCGAPE3juSkOdWVL8WP/uETJoW6hwEr9bUnmAGqZCJcsK9N3CgXRdJOtDmDtI1DMU8CVBqHd/6YS7BVgRm90oHAUlTCWgQ38Wg2M+2IQg7U4lcF/L09NNsK9qaoFGICGtW62MJQXIhs7tNxKUdxNZGSK+FQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788718545; c=relaxed/simple; bh=OTVoe5G0mX++8NPtO9HZ7bmzip8PKVVaUKocL5CJV3Q=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Al7l5lMYlGnffHJBwM7x8ZstXPH0Q9kCMXhYaMUu9EDxntM519Ox03Yowa6z6Tb6oYmvBxlE30KVX4A5twNAu6tgsjDHw98DtE0G00rRaTlj1eUpEw/0ZsKsudiJxihU0x4tOREOD6VpAXYnkkyD83gP0nRyLOhou8erxgOtDlQ= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=manguebit.org; spf=pass smtp.mailfrom=manguebit.org; dkim=pass (2048-bit key) header.d=manguebit.org header.i=@manguebit.org header.b=9ALRMntH; arc=none smtp.client-ip=143.255.12.172 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=manguebit.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=manguebit.org Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=manguebit.org header.i=@manguebit.org header.b="9ALRMntH" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=manguebit.org; s=dkim; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Content-Type:Reply-To: Content-ID:Content-Description; bh=8JY6D5h4XISeZ33LRjcFo1CnVUWUv5sNd1b3XoLM6mM=; b=9ALRMntHYxYEYdPtS+ptpvTGiw +BZU/H5SvnEKwzQf+e2CKuuFtyUgFwwyoEV4a/lxbSuNfHMnzFmFO4ZWYkBKQDRRUuy45w85z5JnK UWXIu1y2+4EEg6anLwcKHD0o9Wk2dgx10ydpsh9XRu8seVw46DVndTpNTBG1VxJrqFYfyTYXMhat2 MqzUb9quM7TKbCSB2kZ90N61afvsr4yJXsyPQqpvqldY/GJyq8WYyb6GqZzbRtwjmF2yU+u9sBATY pUaV3MUQBXuKtC1tWd9fCkrgeJZLMvzfl+9qlSRDGCM+/0e5hu2hHanxbqeZHQ36U4twMYJGYmVGt 7rf0hA0w==; Received: from pc by mx1.manguebit.org with local (Exim 4.99.5) id 1x3HP3-00000000nxW-3zZO; Sun, 06 Sep 2026 15:15:41 -0300 From: Paulo Alcantara To: linux-cifs@vger.kernel.org Cc: Namjae Jeon , Ronnie Sahlberg , Shyam Prasad N , Tom Talpey , Bharath SM , stable@vger.kernel.org Subject: [PATCH v2 4/5] smb: client: avoid using uninitialized SIDs in cifs_posix_to_fattr() Date: Sun, 6 Sep 2026 15:15:39 -0300 Message-ID: <20260906181540.647469-4-pc@manguebit.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260906181540.647469-1-pc@manguebit.org> References: <20260906181540.647469-1-pc@manguebit.org> Precedence: bulk X-Mailing-List: linux-cifs@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit cifs_posix_to_fattr() ignores the return value of posix_info_parse(). When a malformed POSIX directory entry is encountered (e.g. invalid SID lengths from an untrusted server), posix_info_parse() returns -1 without populating the 'parsed' struct. The uninitialized stack memory in parsed.owner and parsed.group is then passed to sid_to_id(), which processes the garbage bytes and passes them to request_key() to construct a SID string, potentially leaking kernel stack contents to the userspace idmap daemon. Fix this by checking the return value and skipping the SID-to-id mapping when parsing fails. The remaining fattr fields (timestamps, mode, etc.) are populated directly from the 'info' pointer so they are unaffected. Closes: https://sashiko.dev/#/patchset/20260906172005.627163-1-pc%40manguebit.org Signed-off-by: Paulo Alcantara Cc: Namjae Jeon Cc: Ronnie Sahlberg Cc: Shyam Prasad N Cc: Tom Talpey Cc: Bharath SM Cc: stable@vger.kernel.org --- fs/smb/client/readdir.c | 16 +++++++++++----- 1 file changed, 11 insertions(+), 5 deletions(-) diff --git a/fs/smb/client/readdir.c b/fs/smb/client/readdir.c index 1ea84f4ada39..44c5c863bd2d 100644 --- a/fs/smb/client/readdir.c +++ b/fs/smb/client/readdir.c @@ -244,8 +244,9 @@ cifs_posix_to_fattr(struct cifs_fattr *fattr, struct smb2_posix_info *info, { unsigned int sbflags = cifs_sb_flags(cifs_sb); struct smb2_posix_info_parsed parsed; + int rc; - posix_info_parse(info, NULL, &parsed); + rc = posix_info_parse(info, NULL, &parsed); memset(fattr, 0, sizeof(*fattr)); fattr->cf_uniqueid = le64_to_cpu(info->Inode); @@ -284,10 +285,15 @@ cifs_posix_to_fattr(struct cifs_fattr *fattr, struct smb2_posix_info *info, fattr->cf_uid = cifs_sb->ctx->linux_uid; fattr->cf_gid = cifs_sb->ctx->linux_gid; - if (!(sbflags & CIFS_MOUNT_OVERR_UID)) - sid_to_id(cifs_sb, &parsed.owner, fattr, SIDOWNER); - if (!(sbflags & CIFS_MOUNT_OVERR_GID)) - sid_to_id(cifs_sb, &parsed.group, fattr, SIDGROUP); + if (rc) { + cifs_dbg(VFS, "%s: failed to parse SIDs: %d\n", + __func__, rc); + } else { + if (!(sbflags & CIFS_MOUNT_OVERR_UID)) + sid_to_id(cifs_sb, &parsed.owner, fattr, SIDOWNER); + if (!(sbflags & CIFS_MOUNT_OVERR_GID)) + sid_to_id(cifs_sb, &parsed.group, fattr, SIDGROUP); + } } static void __dir_info_to_fattr(struct cifs_fattr *fattr, const void *info) -- 2.55.0