* [PATCH] smb: client: fix one-byte OOB read in smb2_parse_native_symlink()
@ 2026-09-09 23:07 Paulo Alcantara
2026-09-10 0:03 ` Namjae Jeon
2026-09-10 14:14 ` Paulo Alcantara
0 siblings, 2 replies; 4+ messages in thread
From: Paulo Alcantara @ 2026-09-09 23:07 UTC (permalink / raw)
To: linux-cifs
Cc: Yuanfu Xie, Pali Rohar, Namjae Jeon, Ronnie Sahlberg,
Shyam Prasad N, Tom Talpey, Bharath SM, stable
When parsing a share-root relative native symlink, memcpy copies
smb_target+1 (skipping the leading separator) but uses
strlen(smb_target)+1 as the length, reading one byte past the
allocated buffer.
This fixes the following KASAN splat when accessing an SMB symlink
with a target of '\a\b':
BUG: KASAN: slab-out-of-bounds in smb2_parse_native_symlink+0x4f5/0xca0
Read of size 5 at addr ffff88800878fe21 by task netfsfuzz-execu/1
CPU: 1 UID: 0 PID: 1 Comm: netfsfuzz-execu Tainted: G N
7.2.0-11943-g2709dd5ae32f-dirty #1 PREEMPT(lazy)
Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix,
1996)
Call Trace:
<TASK>
dump_stack_lvl+0x7b/0xa0
print_report+0xd0/0x630
kasan_report+0xe5/0x120
kasan_check_range+0x105/0x1b0
__asan_memcpy+0x23/0x60
smb2_parse_native_symlink+0x4f5/0xca0
parse_reparse_point+0x68a/0x1530
reparse_info_to_fattr+0x752/0xa20
cifs_get_fattr+0x873/0x15b0
cifs_get_inode_info+0xc0/0x310
cifs_lookup+0x308/0xa70
__lookup_slow+0x122/0x2b0
lookup_slow+0x50/0x70
path_lookupat+0x525/0xaf0
filename_lookup+0x1f2/0x550
vfs_statx+0xd1/0x1a0
vfs_fstatat+0x65/0xc0
__do_sys_newfstatat+0x9a/0x120
do_syscall_64+0xdd/0x4a0
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Reported-by: Yuanfu Xie <yuanfuxie@stu.pku.edu.cn>
Fixes: 723f4ef90452 ("cifs: Fix parsing native symlinks relative to the export")
Suggested-by: Pali Rohar <pali@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Cc: Namjae Jeon <linkinjeon@kernel.org>
Cc: Ronnie Sahlberg <ronniesahlberg@gmail.com>
Cc: Shyam Prasad N <sprasad@microsoft.com>
Cc: Tom Talpey <tom@talpey.com>
Cc: Bharath SM <bharathsm@microsoft.com>
Cc: stable@vger.kernel.org
---
fs/smb/client/reparse.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/fs/smb/client/reparse.c b/fs/smb/client/reparse.c
index b6bded042e78..8a1b9e8be5ba 100644
--- a/fs/smb/client/reparse.c
+++ b/fs/smb/client/reparse.c
@@ -971,7 +971,8 @@ int smb2_parse_native_symlink(char **target, const char *buf, unsigned int len,
linux_target[i*3 + 1] = '.';
linux_target[i*3 + 2] = sep;
}
- memcpy(linux_target + levels*3, smb_target+1, smb_target_len); /* +1 to skip leading sep */
+ /* +1 to skip leading sep */
+ memcpy(linux_target + levels*3, smb_target+1, smb_target_len-1);
} else {
/*
* This is either an absolute symlink in POSIX-style format
--
2.55.0
^ permalink raw reply related [flat|nested] 4+ messages in thread
* Re: [PATCH] smb: client: fix one-byte OOB read in smb2_parse_native_symlink()
2026-09-09 23:07 [PATCH] smb: client: fix one-byte OOB read in smb2_parse_native_symlink() Paulo Alcantara
@ 2026-09-10 0:03 ` Namjae Jeon
2026-09-10 0:27 ` Pali Rohár
2026-09-10 14:14 ` Paulo Alcantara
1 sibling, 1 reply; 4+ messages in thread
From: Namjae Jeon @ 2026-09-10 0:03 UTC (permalink / raw)
To: Paulo Alcantara
Cc: linux-cifs, Yuanfu Xie, Pali Rohar, Ronnie Sahlberg,
Shyam Prasad N, Tom Talpey, Bharath SM, stable
On Thu, Sep 10, 2026 at 8:07 AM Paulo Alcantara <pc@manguebit.org> wrote:
>
> When parsing a share-root relative native symlink, memcpy copies
> smb_target+1 (skipping the leading separator) but uses
> strlen(smb_target)+1 as the length, reading one byte past the
> allocated buffer.
>
> This fixes the following KASAN splat when accessing an SMB symlink
> with a target of '\a\b':
>
> BUG: KASAN: slab-out-of-bounds in smb2_parse_native_symlink+0x4f5/0xca0
> Read of size 5 at addr ffff88800878fe21 by task netfsfuzz-execu/1
> CPU: 1 UID: 0 PID: 1 Comm: netfsfuzz-execu Tainted: G N
> 7.2.0-11943-g2709dd5ae32f-dirty #1 PREEMPT(lazy)
> Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix,
> 1996)
> Call Trace:
> <TASK>
> dump_stack_lvl+0x7b/0xa0
> print_report+0xd0/0x630
> kasan_report+0xe5/0x120
> kasan_check_range+0x105/0x1b0
> __asan_memcpy+0x23/0x60
> smb2_parse_native_symlink+0x4f5/0xca0
> parse_reparse_point+0x68a/0x1530
> reparse_info_to_fattr+0x752/0xa20
> cifs_get_fattr+0x873/0x15b0
> cifs_get_inode_info+0xc0/0x310
> cifs_lookup+0x308/0xa70
> __lookup_slow+0x122/0x2b0
> lookup_slow+0x50/0x70
> path_lookupat+0x525/0xaf0
> filename_lookup+0x1f2/0x550
> vfs_statx+0xd1/0x1a0
> vfs_fstatat+0x65/0xc0
> __do_sys_newfstatat+0x9a/0x120
> do_syscall_64+0xdd/0x4a0
> entry_SYSCALL_64_after_hwframe+0x77/0x7f
>
> Reported-by: Yuanfu Xie <yuanfuxie@stu.pku.edu.cn>
> Fixes: 723f4ef90452 ("cifs: Fix parsing native symlinks relative to the export")
> Suggested-by: Pali Rohar <pali@kernel.org>
> Signed-off-by: Paulo Alcantara <pc@manguebit.org>
> Cc: Namjae Jeon <linkinjeon@kernel.org>
> Cc: Ronnie Sahlberg <ronniesahlberg@gmail.com>
> Cc: Shyam Prasad N <sprasad@microsoft.com>
> Cc: Tom Talpey <tom@talpey.com>
> Cc: Bharath SM <bharathsm@microsoft.com>
> Cc: stable@vger.kernel.org
Reviewed-by: Namjae Jeon <linkinjeon@kernel.org>
Thanks!
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH] smb: client: fix one-byte OOB read in smb2_parse_native_symlink()
2026-09-10 0:03 ` Namjae Jeon
@ 2026-09-10 0:27 ` Pali Rohár
0 siblings, 0 replies; 4+ messages in thread
From: Pali Rohár @ 2026-09-10 0:27 UTC (permalink / raw)
To: Namjae Jeon
Cc: Paulo Alcantara, linux-cifs, Yuanfu Xie, Ronnie Sahlberg,
Shyam Prasad N, Tom Talpey, Bharath SM, stable
On Thursday 10 September 2026 09:03:32 Namjae Jeon wrote:
> On Thu, Sep 10, 2026 at 8:07 AM Paulo Alcantara <pc@manguebit.org> wrote:
> >
> > When parsing a share-root relative native symlink, memcpy copies
> > smb_target+1 (skipping the leading separator) but uses
> > strlen(smb_target)+1 as the length, reading one byte past the
> > allocated buffer.
> >
> > This fixes the following KASAN splat when accessing an SMB symlink
> > with a target of '\a\b':
> >
> > BUG: KASAN: slab-out-of-bounds in smb2_parse_native_symlink+0x4f5/0xca0
> > Read of size 5 at addr ffff88800878fe21 by task netfsfuzz-execu/1
> > CPU: 1 UID: 0 PID: 1 Comm: netfsfuzz-execu Tainted: G N
> > 7.2.0-11943-g2709dd5ae32f-dirty #1 PREEMPT(lazy)
> > Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix,
> > 1996)
> > Call Trace:
> > <TASK>
> > dump_stack_lvl+0x7b/0xa0
> > print_report+0xd0/0x630
> > kasan_report+0xe5/0x120
> > kasan_check_range+0x105/0x1b0
> > __asan_memcpy+0x23/0x60
> > smb2_parse_native_symlink+0x4f5/0xca0
> > parse_reparse_point+0x68a/0x1530
> > reparse_info_to_fattr+0x752/0xa20
> > cifs_get_fattr+0x873/0x15b0
> > cifs_get_inode_info+0xc0/0x310
> > cifs_lookup+0x308/0xa70
> > __lookup_slow+0x122/0x2b0
> > lookup_slow+0x50/0x70
> > path_lookupat+0x525/0xaf0
> > filename_lookup+0x1f2/0x550
> > vfs_statx+0xd1/0x1a0
> > vfs_fstatat+0x65/0xc0
> > __do_sys_newfstatat+0x9a/0x120
> > do_syscall_64+0xdd/0x4a0
> > entry_SYSCALL_64_after_hwframe+0x77/0x7f
> >
> > Reported-by: Yuanfu Xie <yuanfuxie@stu.pku.edu.cn>
> > Fixes: 723f4ef90452 ("cifs: Fix parsing native symlinks relative to the export")
> > Suggested-by: Pali Rohar <pali@kernel.org>
> > Signed-off-by: Paulo Alcantara <pc@manguebit.org>
> > Cc: Namjae Jeon <linkinjeon@kernel.org>
> > Cc: Ronnie Sahlberg <ronniesahlberg@gmail.com>
> > Cc: Shyam Prasad N <sprasad@microsoft.com>
> > Cc: Tom Talpey <tom@talpey.com>
> > Cc: Bharath SM <bharathsm@microsoft.com>
> > Cc: stable@vger.kernel.org
> Reviewed-by: Namjae Jeon <linkinjeon@kernel.org>
> Thanks!
Thank you for preparing the change!
Reviewed-by: Pali Rohár <pali@kernel.org>
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH] smb: client: fix one-byte OOB read in smb2_parse_native_symlink()
2026-09-09 23:07 [PATCH] smb: client: fix one-byte OOB read in smb2_parse_native_symlink() Paulo Alcantara
2026-09-10 0:03 ` Namjae Jeon
@ 2026-09-10 14:14 ` Paulo Alcantara
1 sibling, 0 replies; 4+ messages in thread
From: Paulo Alcantara @ 2026-09-10 14:14 UTC (permalink / raw)
To: linux-cifs
Cc: Yuanfu Xie, Pali Rohar, Namjae Jeon, Ronnie Sahlberg,
Shyam Prasad N, Tom Talpey, Bharath SM, stable
Paulo Alcantara <pc@manguebit.org> writes:
> When parsing a share-root relative native symlink, memcpy copies
> smb_target+1 (skipping the leading separator) but uses
> strlen(smb_target)+1 as the length, reading one byte past the
> allocated buffer.
>
> This fixes the following KASAN splat when accessing an SMB symlink
> with a target of '\a\b':
>
> BUG: KASAN: slab-out-of-bounds in smb2_parse_native_symlink+0x4f5/0xca0
> Read of size 5 at addr ffff88800878fe21 by task netfsfuzz-execu/1
> CPU: 1 UID: 0 PID: 1 Comm: netfsfuzz-execu Tainted: G N
> 7.2.0-11943-g2709dd5ae32f-dirty #1 PREEMPT(lazy)
> Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix,
> 1996)
> Call Trace:
> <TASK>
> dump_stack_lvl+0x7b/0xa0
> print_report+0xd0/0x630
> kasan_report+0xe5/0x120
> kasan_check_range+0x105/0x1b0
> __asan_memcpy+0x23/0x60
> smb2_parse_native_symlink+0x4f5/0xca0
> parse_reparse_point+0x68a/0x1530
> reparse_info_to_fattr+0x752/0xa20
> cifs_get_fattr+0x873/0x15b0
> cifs_get_inode_info+0xc0/0x310
> cifs_lookup+0x308/0xa70
> __lookup_slow+0x122/0x2b0
> lookup_slow+0x50/0x70
> path_lookupat+0x525/0xaf0
> filename_lookup+0x1f2/0x550
> vfs_statx+0xd1/0x1a0
> vfs_fstatat+0x65/0xc0
> __do_sys_newfstatat+0x9a/0x120
> do_syscall_64+0xdd/0x4a0
> entry_SYSCALL_64_after_hwframe+0x77/0x7f
> ...
Applied.
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-09-10 14:14 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-09 23:07 [PATCH] smb: client: fix one-byte OOB read in smb2_parse_native_symlink() Paulo Alcantara
2026-09-10 0:03 ` Namjae Jeon
2026-09-10 0:27 ` Pali Rohár
2026-09-10 14:14 ` Paulo Alcantara
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox