Linux CIFS filesystem development
 help / color / mirror / Atom feed
* [PATCH] smb: client: fix one-byte OOB read in smb2_parse_native_symlink()
@ 2026-09-09 23:07 Paulo Alcantara
  2026-09-10  0:03 ` Namjae Jeon
  2026-09-10 14:14 ` Paulo Alcantara
  0 siblings, 2 replies; 4+ messages in thread
From: Paulo Alcantara @ 2026-09-09 23:07 UTC (permalink / raw)
  To: linux-cifs
  Cc: Yuanfu Xie, Pali Rohar, Namjae Jeon, Ronnie Sahlberg,
	Shyam Prasad N, Tom Talpey, Bharath SM, stable

When parsing a share-root relative native symlink, memcpy copies
smb_target+1 (skipping the leading separator) but uses
strlen(smb_target)+1 as the length, reading one byte past the
allocated buffer.

This fixes the following KASAN splat when accessing an SMB symlink
with a target of '\a\b':

  BUG: KASAN: slab-out-of-bounds in smb2_parse_native_symlink+0x4f5/0xca0
  Read of size 5 at addr ffff88800878fe21 by task netfsfuzz-execu/1
  CPU: 1 UID: 0 PID: 1 Comm: netfsfuzz-execu Tainted: G N
  7.2.0-11943-g2709dd5ae32f-dirty #1 PREEMPT(lazy)
  Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix,
  1996)
  Call Trace:
   <TASK>
   dump_stack_lvl+0x7b/0xa0
   print_report+0xd0/0x630
   kasan_report+0xe5/0x120
   kasan_check_range+0x105/0x1b0
   __asan_memcpy+0x23/0x60
   smb2_parse_native_symlink+0x4f5/0xca0
   parse_reparse_point+0x68a/0x1530
   reparse_info_to_fattr+0x752/0xa20
   cifs_get_fattr+0x873/0x15b0
   cifs_get_inode_info+0xc0/0x310
   cifs_lookup+0x308/0xa70
   __lookup_slow+0x122/0x2b0
   lookup_slow+0x50/0x70
   path_lookupat+0x525/0xaf0
   filename_lookup+0x1f2/0x550
   vfs_statx+0xd1/0x1a0
   vfs_fstatat+0x65/0xc0
   __do_sys_newfstatat+0x9a/0x120
   do_syscall_64+0xdd/0x4a0
   entry_SYSCALL_64_after_hwframe+0x77/0x7f

Reported-by: Yuanfu Xie <yuanfuxie@stu.pku.edu.cn>
Fixes: 723f4ef90452 ("cifs: Fix parsing native symlinks relative to the export")
Suggested-by: Pali Rohar <pali@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Cc: Namjae Jeon <linkinjeon@kernel.org>
Cc: Ronnie Sahlberg <ronniesahlberg@gmail.com>
Cc: Shyam Prasad N <sprasad@microsoft.com>
Cc: Tom Talpey <tom@talpey.com>
Cc: Bharath SM <bharathsm@microsoft.com>
Cc: stable@vger.kernel.org
---
 fs/smb/client/reparse.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/fs/smb/client/reparse.c b/fs/smb/client/reparse.c
index b6bded042e78..8a1b9e8be5ba 100644
--- a/fs/smb/client/reparse.c
+++ b/fs/smb/client/reparse.c
@@ -971,7 +971,8 @@ int smb2_parse_native_symlink(char **target, const char *buf, unsigned int len,
 			linux_target[i*3 + 1] = '.';
 			linux_target[i*3 + 2] = sep;
 		}
-		memcpy(linux_target + levels*3, smb_target+1, smb_target_len); /* +1 to skip leading sep */
+		/* +1 to skip leading sep */
+		memcpy(linux_target + levels*3, smb_target+1, smb_target_len-1);
 	} else {
 		/*
 		 * This is either an absolute symlink in POSIX-style format
-- 
2.55.0


^ permalink raw reply related	[flat|nested] 4+ messages in thread

* Re: [PATCH] smb: client: fix one-byte OOB read in smb2_parse_native_symlink()
  2026-09-09 23:07 [PATCH] smb: client: fix one-byte OOB read in smb2_parse_native_symlink() Paulo Alcantara
@ 2026-09-10  0:03 ` Namjae Jeon
  2026-09-10  0:27   ` Pali Rohár
  2026-09-10 14:14 ` Paulo Alcantara
  1 sibling, 1 reply; 4+ messages in thread
From: Namjae Jeon @ 2026-09-10  0:03 UTC (permalink / raw)
  To: Paulo Alcantara
  Cc: linux-cifs, Yuanfu Xie, Pali Rohar, Ronnie Sahlberg,
	Shyam Prasad N, Tom Talpey, Bharath SM, stable

On Thu, Sep 10, 2026 at 8:07 AM Paulo Alcantara <pc@manguebit.org> wrote:
>
> When parsing a share-root relative native symlink, memcpy copies
> smb_target+1 (skipping the leading separator) but uses
> strlen(smb_target)+1 as the length, reading one byte past the
> allocated buffer.
>
> This fixes the following KASAN splat when accessing an SMB symlink
> with a target of '\a\b':
>
>   BUG: KASAN: slab-out-of-bounds in smb2_parse_native_symlink+0x4f5/0xca0
>   Read of size 5 at addr ffff88800878fe21 by task netfsfuzz-execu/1
>   CPU: 1 UID: 0 PID: 1 Comm: netfsfuzz-execu Tainted: G N
>   7.2.0-11943-g2709dd5ae32f-dirty #1 PREEMPT(lazy)
>   Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix,
>   1996)
>   Call Trace:
>    <TASK>
>    dump_stack_lvl+0x7b/0xa0
>    print_report+0xd0/0x630
>    kasan_report+0xe5/0x120
>    kasan_check_range+0x105/0x1b0
>    __asan_memcpy+0x23/0x60
>    smb2_parse_native_symlink+0x4f5/0xca0
>    parse_reparse_point+0x68a/0x1530
>    reparse_info_to_fattr+0x752/0xa20
>    cifs_get_fattr+0x873/0x15b0
>    cifs_get_inode_info+0xc0/0x310
>    cifs_lookup+0x308/0xa70
>    __lookup_slow+0x122/0x2b0
>    lookup_slow+0x50/0x70
>    path_lookupat+0x525/0xaf0
>    filename_lookup+0x1f2/0x550
>    vfs_statx+0xd1/0x1a0
>    vfs_fstatat+0x65/0xc0
>    __do_sys_newfstatat+0x9a/0x120
>    do_syscall_64+0xdd/0x4a0
>    entry_SYSCALL_64_after_hwframe+0x77/0x7f
>
> Reported-by: Yuanfu Xie <yuanfuxie@stu.pku.edu.cn>
> Fixes: 723f4ef90452 ("cifs: Fix parsing native symlinks relative to the export")
> Suggested-by: Pali Rohar <pali@kernel.org>
> Signed-off-by: Paulo Alcantara <pc@manguebit.org>
> Cc: Namjae Jeon <linkinjeon@kernel.org>
> Cc: Ronnie Sahlberg <ronniesahlberg@gmail.com>
> Cc: Shyam Prasad N <sprasad@microsoft.com>
> Cc: Tom Talpey <tom@talpey.com>
> Cc: Bharath SM <bharathsm@microsoft.com>
> Cc: stable@vger.kernel.org
Reviewed-by: Namjae Jeon <linkinjeon@kernel.org>
Thanks!

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH] smb: client: fix one-byte OOB read in smb2_parse_native_symlink()
  2026-09-10  0:03 ` Namjae Jeon
@ 2026-09-10  0:27   ` Pali Rohár
  0 siblings, 0 replies; 4+ messages in thread
From: Pali Rohár @ 2026-09-10  0:27 UTC (permalink / raw)
  To: Namjae Jeon
  Cc: Paulo Alcantara, linux-cifs, Yuanfu Xie, Ronnie Sahlberg,
	Shyam Prasad N, Tom Talpey, Bharath SM, stable

On Thursday 10 September 2026 09:03:32 Namjae Jeon wrote:
> On Thu, Sep 10, 2026 at 8:07 AM Paulo Alcantara <pc@manguebit.org> wrote:
> >
> > When parsing a share-root relative native symlink, memcpy copies
> > smb_target+1 (skipping the leading separator) but uses
> > strlen(smb_target)+1 as the length, reading one byte past the
> > allocated buffer.
> >
> > This fixes the following KASAN splat when accessing an SMB symlink
> > with a target of '\a\b':
> >
> >   BUG: KASAN: slab-out-of-bounds in smb2_parse_native_symlink+0x4f5/0xca0
> >   Read of size 5 at addr ffff88800878fe21 by task netfsfuzz-execu/1
> >   CPU: 1 UID: 0 PID: 1 Comm: netfsfuzz-execu Tainted: G N
> >   7.2.0-11943-g2709dd5ae32f-dirty #1 PREEMPT(lazy)
> >   Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix,
> >   1996)
> >   Call Trace:
> >    <TASK>
> >    dump_stack_lvl+0x7b/0xa0
> >    print_report+0xd0/0x630
> >    kasan_report+0xe5/0x120
> >    kasan_check_range+0x105/0x1b0
> >    __asan_memcpy+0x23/0x60
> >    smb2_parse_native_symlink+0x4f5/0xca0
> >    parse_reparse_point+0x68a/0x1530
> >    reparse_info_to_fattr+0x752/0xa20
> >    cifs_get_fattr+0x873/0x15b0
> >    cifs_get_inode_info+0xc0/0x310
> >    cifs_lookup+0x308/0xa70
> >    __lookup_slow+0x122/0x2b0
> >    lookup_slow+0x50/0x70
> >    path_lookupat+0x525/0xaf0
> >    filename_lookup+0x1f2/0x550
> >    vfs_statx+0xd1/0x1a0
> >    vfs_fstatat+0x65/0xc0
> >    __do_sys_newfstatat+0x9a/0x120
> >    do_syscall_64+0xdd/0x4a0
> >    entry_SYSCALL_64_after_hwframe+0x77/0x7f
> >
> > Reported-by: Yuanfu Xie <yuanfuxie@stu.pku.edu.cn>
> > Fixes: 723f4ef90452 ("cifs: Fix parsing native symlinks relative to the export")
> > Suggested-by: Pali Rohar <pali@kernel.org>
> > Signed-off-by: Paulo Alcantara <pc@manguebit.org>
> > Cc: Namjae Jeon <linkinjeon@kernel.org>
> > Cc: Ronnie Sahlberg <ronniesahlberg@gmail.com>
> > Cc: Shyam Prasad N <sprasad@microsoft.com>
> > Cc: Tom Talpey <tom@talpey.com>
> > Cc: Bharath SM <bharathsm@microsoft.com>
> > Cc: stable@vger.kernel.org
> Reviewed-by: Namjae Jeon <linkinjeon@kernel.org>
> Thanks!

Thank you for preparing the change!

Reviewed-by: Pali Rohár <pali@kernel.org>

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH] smb: client: fix one-byte OOB read in smb2_parse_native_symlink()
  2026-09-09 23:07 [PATCH] smb: client: fix one-byte OOB read in smb2_parse_native_symlink() Paulo Alcantara
  2026-09-10  0:03 ` Namjae Jeon
@ 2026-09-10 14:14 ` Paulo Alcantara
  1 sibling, 0 replies; 4+ messages in thread
From: Paulo Alcantara @ 2026-09-10 14:14 UTC (permalink / raw)
  To: linux-cifs
  Cc: Yuanfu Xie, Pali Rohar, Namjae Jeon, Ronnie Sahlberg,
	Shyam Prasad N, Tom Talpey, Bharath SM, stable

Paulo Alcantara <pc@manguebit.org> writes:

> When parsing a share-root relative native symlink, memcpy copies
> smb_target+1 (skipping the leading separator) but uses
> strlen(smb_target)+1 as the length, reading one byte past the
> allocated buffer.
>
> This fixes the following KASAN splat when accessing an SMB symlink
> with a target of '\a\b':
>
>   BUG: KASAN: slab-out-of-bounds in smb2_parse_native_symlink+0x4f5/0xca0
>   Read of size 5 at addr ffff88800878fe21 by task netfsfuzz-execu/1
>   CPU: 1 UID: 0 PID: 1 Comm: netfsfuzz-execu Tainted: G N
>   7.2.0-11943-g2709dd5ae32f-dirty #1 PREEMPT(lazy)
>   Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix,
>   1996)
>   Call Trace:
>    <TASK>
>    dump_stack_lvl+0x7b/0xa0
>    print_report+0xd0/0x630
>    kasan_report+0xe5/0x120
>    kasan_check_range+0x105/0x1b0
>    __asan_memcpy+0x23/0x60
>    smb2_parse_native_symlink+0x4f5/0xca0
>    parse_reparse_point+0x68a/0x1530
>    reparse_info_to_fattr+0x752/0xa20
>    cifs_get_fattr+0x873/0x15b0
>    cifs_get_inode_info+0xc0/0x310
>    cifs_lookup+0x308/0xa70
>    __lookup_slow+0x122/0x2b0
>    lookup_slow+0x50/0x70
>    path_lookupat+0x525/0xaf0
>    filename_lookup+0x1f2/0x550
>    vfs_statx+0xd1/0x1a0
>    vfs_fstatat+0x65/0xc0
>    __do_sys_newfstatat+0x9a/0x120
>    do_syscall_64+0xdd/0x4a0
>    entry_SYSCALL_64_after_hwframe+0x77/0x7f
> ...

Applied.

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-09-10 14:14 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-09 23:07 [PATCH] smb: client: fix one-byte OOB read in smb2_parse_native_symlink() Paulo Alcantara
2026-09-10  0:03 ` Namjae Jeon
2026-09-10  0:27   ` Pali Rohár
2026-09-10 14:14 ` Paulo Alcantara

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox