* [PATCH 1/2] smb: client: fix unaligned access in WSL reparse point parser
@ 2026-09-14 1:10 Paulo Alcantara
2026-09-14 1:10 ` [PATCH 2/2] smb: client: fix fattr leaking on wsl_to_fattr() failure Paulo Alcantara
` (2 more replies)
0 siblings, 3 replies; 6+ messages in thread
From: Paulo Alcantara @ 2026-09-14 1:10 UTC (permalink / raw)
To: linux-cifs
Cc: David Howells, Tom Talpey, Shyam Prasad N, Ronnie Sahlberg,
Bharath SM, Namjae Jeon, stable
When wsl_to_fattr() parses WSL extended attributes, it computes a
payload pointer from ea->ea_data + ea_name_length + 1. Since the
smb2_file_full_ea_info struct is __packed and all WSL xattr names are
6 bytes long, the value pointer always lands at an odd byte offset,
never satisfying __le32 or __le64 alignment requirements.
The code then casts this pointer to __le32 * or __le64 * and
dereferences it directly, which may cause alignment faults on some
architectures.
Replace all such casts with get_unaligned_le32() and
get_unaligned_le64() in reparse_mkdev(), wsl_make_kuid(),
wsl_make_kgid() and wsl_to_fattr().
Closes: https://sashiko.dev/#/patchset/20260906200517.725015-1-pc%40manguebit.org
Fixes: 78e26bec4d6d ("smb: client: parse uid, gid, mode and dev from WSL reparse points")
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Cc: David Howells <dhowells@redhat.com>
Cc: Tom Talpey <tom@talpey.com>
Cc: Shyam Prasad N <sprasad@microsoft.com>
Cc: Ronnie Sahlberg <ronniesahlberg@gmail.com>
Cc: Bharath SM <bharathsm@microsoft.com>
Cc: Namjae Jeon <linkinjeon@kernel.org>
Cc: stable@vger.kernel.org
---
fs/smb/client/reparse.c | 4 ++--
fs/smb/client/reparse.h | 7 ++++---
2 files changed, 6 insertions(+), 5 deletions(-)
diff --git a/fs/smb/client/reparse.c b/fs/smb/client/reparse.c
index 9e31fce7e0a5..6ac69f4d391a 100644
--- a/fs/smb/client/reparse.c
+++ b/fs/smb/client/reparse.c
@@ -1201,9 +1201,9 @@ static bool wsl_to_fattr(struct cifs_open_info_data *data,
fattr->cf_gid = wsl_make_kgid(cifs_sb, v);
} else if (!strncmp(name, SMB2_WSL_XATTR_MODE, nlen)) {
/* File type in reparse point tag and in xattr mode must match. */
- if (S_DT(fattr->cf_mode) != S_DT(le32_to_cpu(*(__le32 *)v)))
+ if (S_DT(fattr->cf_mode) != S_DT(get_unaligned_le32(v)))
return false;
- fattr->cf_mode = (umode_t)le32_to_cpu(*(__le32 *)v);
+ fattr->cf_mode = (umode_t)get_unaligned_le32(v);
} else if (!strncmp(name, SMB2_WSL_XATTR_DEV, nlen)) {
fattr->cf_rdev = reparse_mkdev(v);
have_xattr_dev = true;
diff --git a/fs/smb/client/reparse.h b/fs/smb/client/reparse.h
index 49efd85b1e94..05b2cecb4495 100644
--- a/fs/smb/client/reparse.h
+++ b/fs/smb/client/reparse.h
@@ -9,6 +9,7 @@
#include <linux/fs.h>
#include <linux/stat.h>
#include <linux/uidgid.h>
+#include <linux/unaligned.h>
#include "fs_context.h"
#include "cifsglob.h"
#include "../common/smbfsctl.h"
@@ -23,7 +24,7 @@
static inline dev_t reparse_mkdev(void *ptr)
{
- u64 v = le64_to_cpu(*(__le64 *)ptr);
+ u64 v = get_unaligned_le64(ptr);
return MKDEV(v & 0xffffffff, v >> 32);
}
@@ -31,7 +32,7 @@ static inline dev_t reparse_mkdev(void *ptr)
static inline kuid_t wsl_make_kuid(struct cifs_sb_info *cifs_sb,
void *ptr)
{
- u32 uid = le32_to_cpu(*(__le32 *)ptr);
+ u32 uid = get_unaligned_le32(ptr);
if (cifs_sb_flags(cifs_sb) & CIFS_MOUNT_OVERR_UID)
return cifs_sb->ctx->linux_uid;
@@ -41,7 +42,7 @@ static inline kuid_t wsl_make_kuid(struct cifs_sb_info *cifs_sb,
static inline kgid_t wsl_make_kgid(struct cifs_sb_info *cifs_sb,
void *ptr)
{
- u32 gid = le32_to_cpu(*(__le32 *)ptr);
+ u32 gid = get_unaligned_le32(ptr);
if (cifs_sb_flags(cifs_sb) & CIFS_MOUNT_OVERR_GID)
return cifs_sb->ctx->linux_gid;
--
2.55.0
^ permalink raw reply related [flat|nested] 6+ messages in thread
* [PATCH 2/2] smb: client: fix fattr leaking on wsl_to_fattr() failure
2026-09-14 1:10 [PATCH 1/2] smb: client: fix unaligned access in WSL reparse point parser Paulo Alcantara
@ 2026-09-14 1:10 ` Paulo Alcantara
2026-09-15 0:13 ` Namjae Jeon
2026-09-15 14:29 ` Paulo Alcantara
2026-09-15 0:12 ` [PATCH 1/2] smb: client: fix unaligned access in WSL reparse point parser Namjae Jeon
2026-09-15 14:29 ` Paulo Alcantara
2 siblings, 2 replies; 6+ messages in thread
From: Paulo Alcantara @ 2026-09-14 1:10 UTC (permalink / raw)
To: linux-cifs
Cc: David Howells, Tom Talpey, Shyam Prasad N, Ronnie Sahlberg,
Bharath SM, Namjae Jeon, stable
wsl_to_fattr() mutates fattr fields as it parses each WSL EA. If
validation later fails, the function returns false with partially
mutated fattr fields that callers do not reset.
Fix this by parsing into local variables and only committing them to
fattr on success.
Closes: https://sashiko.dev/#/patchset/20260906200517.725015-1-pc%40manguebit.org
Fixes: 78e26bec4d6d ("smb: client: parse uid, gid, mode and dev from WSL reparse points")
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Cc: David Howells <dhowells@redhat.com>
Cc: Tom Talpey <tom@talpey.com>
Cc: Shyam Prasad N <sprasad@microsoft.com>
Cc: Ronnie Sahlberg <ronniesahlberg@gmail.com>
Cc: Bharath SM <bharathsm@microsoft.com>
Cc: Namjae Jeon <linkinjeon@kernel.org>
Cc: stable@vger.kernel.org
---
fs/smb/client/reparse.c | 34 +++++++++++++++++++---------------
1 file changed, 19 insertions(+), 15 deletions(-)
diff --git a/fs/smb/client/reparse.c b/fs/smb/client/reparse.c
index 6ac69f4d391a..3a27773186ae 100644
--- a/fs/smb/client/reparse.c
+++ b/fs/smb/client/reparse.c
@@ -1149,29 +1149,30 @@ static bool wsl_to_fattr(struct cifs_open_info_data *data,
u32 tag, struct cifs_fattr *fattr)
{
unsigned int sbflags = cifs_sb_flags(cifs_sb);
+ kuid_t uid = cifs_sb->ctx->linux_uid;
+ kgid_t gid = cifs_sb->ctx->linux_gid;
struct smb2_file_full_ea_info *ea;
bool have_xattr_dev = false;
+ dev_t rdev = 0;
+ umode_t mode;
u32 next = 0;
- fattr->cf_uid = cifs_sb->ctx->linux_uid;
- fattr->cf_gid = cifs_sb->ctx->linux_gid;
-
- fattr->cf_mode &= ~S_IFMT;
+ mode = fattr->cf_mode & ~S_IFMT;
switch (tag) {
case IO_REPARSE_TAG_LX_SYMLINK:
- fattr->cf_mode |= S_IFLNK;
+ mode |= S_IFLNK;
break;
case IO_REPARSE_TAG_LX_FIFO:
- fattr->cf_mode |= S_IFIFO;
+ mode |= S_IFIFO;
break;
case IO_REPARSE_TAG_AF_UNIX:
- fattr->cf_mode |= S_IFSOCK;
+ mode |= S_IFSOCK;
break;
case IO_REPARSE_TAG_LX_CHR:
- fattr->cf_mode |= S_IFCHR;
+ mode |= S_IFCHR;
break;
case IO_REPARSE_TAG_LX_BLK:
- fattr->cf_mode |= S_IFBLK;
+ mode |= S_IFBLK;
break;
}
@@ -1195,26 +1196,29 @@ static bool wsl_to_fattr(struct cifs_open_info_data *data,
if (!strncmp(name, SMB2_WSL_XATTR_UID, nlen)) {
if (!(sbflags & CIFS_MOUNT_OVERR_UID))
- fattr->cf_uid = wsl_make_kuid(cifs_sb, v);
+ uid = wsl_make_kuid(cifs_sb, v);
} else if (!strncmp(name, SMB2_WSL_XATTR_GID, nlen)) {
if (!(sbflags & CIFS_MOUNT_OVERR_GID))
- fattr->cf_gid = wsl_make_kgid(cifs_sb, v);
+ gid = wsl_make_kgid(cifs_sb, v);
} else if (!strncmp(name, SMB2_WSL_XATTR_MODE, nlen)) {
/* File type in reparse point tag and in xattr mode must match. */
- if (S_DT(fattr->cf_mode) != S_DT(get_unaligned_le32(v)))
+ if (S_DT(mode) != S_DT(get_unaligned_le32(v)))
return false;
- fattr->cf_mode = (umode_t)get_unaligned_le32(v);
+ mode = get_unaligned_le32(v);
} else if (!strncmp(name, SMB2_WSL_XATTR_DEV, nlen)) {
- fattr->cf_rdev = reparse_mkdev(v);
+ rdev = reparse_mkdev(v);
have_xattr_dev = true;
}
} while (next);
out:
-
/* Major and minor numbers for char and block devices are mandatory. */
if (!have_xattr_dev && (tag == IO_REPARSE_TAG_LX_CHR || tag == IO_REPARSE_TAG_LX_BLK))
return false;
+ fattr->cf_uid = uid;
+ fattr->cf_gid = gid;
+ fattr->cf_mode = mode;
+ fattr->cf_rdev = rdev;
return true;
}
--
2.55.0
^ permalink raw reply related [flat|nested] 6+ messages in thread
* Re: [PATCH 1/2] smb: client: fix unaligned access in WSL reparse point parser
2026-09-14 1:10 [PATCH 1/2] smb: client: fix unaligned access in WSL reparse point parser Paulo Alcantara
2026-09-14 1:10 ` [PATCH 2/2] smb: client: fix fattr leaking on wsl_to_fattr() failure Paulo Alcantara
@ 2026-09-15 0:12 ` Namjae Jeon
2026-09-15 14:29 ` Paulo Alcantara
2 siblings, 0 replies; 6+ messages in thread
From: Namjae Jeon @ 2026-09-15 0:12 UTC (permalink / raw)
To: Paulo Alcantara
Cc: linux-cifs, David Howells, Tom Talpey, Shyam Prasad N,
Ronnie Sahlberg, Bharath SM, stable
On Mon, Sep 14, 2026 at 10:10 AM Paulo Alcantara <pc@manguebit.org> wrote:
>
> When wsl_to_fattr() parses WSL extended attributes, it computes a
> payload pointer from ea->ea_data + ea_name_length + 1. Since the
> smb2_file_full_ea_info struct is __packed and all WSL xattr names are
> 6 bytes long, the value pointer always lands at an odd byte offset,
> never satisfying __le32 or __le64 alignment requirements.
>
> The code then casts this pointer to __le32 * or __le64 * and
> dereferences it directly, which may cause alignment faults on some
> architectures.
>
> Replace all such casts with get_unaligned_le32() and
> get_unaligned_le64() in reparse_mkdev(), wsl_make_kuid(),
> wsl_make_kgid() and wsl_to_fattr().
>
> Closes: https://sashiko.dev/#/patchset/20260906200517.725015-1-pc%40manguebit.org
> Fixes: 78e26bec4d6d ("smb: client: parse uid, gid, mode and dev from WSL reparse points")
> Signed-off-by: Paulo Alcantara <pc@manguebit.org>
> Cc: David Howells <dhowells@redhat.com>
> Cc: Tom Talpey <tom@talpey.com>
> Cc: Shyam Prasad N <sprasad@microsoft.com>
> Cc: Ronnie Sahlberg <ronniesahlberg@gmail.com>
> Cc: Bharath SM <bharathsm@microsoft.com>
> Cc: Namjae Jeon <linkinjeon@kernel.org>
> Cc: stable@vger.kernel.org
Reviewed-by: Namjae Jeon <linkinjeon@kernel.org>
Thanks!
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH 2/2] smb: client: fix fattr leaking on wsl_to_fattr() failure
2026-09-14 1:10 ` [PATCH 2/2] smb: client: fix fattr leaking on wsl_to_fattr() failure Paulo Alcantara
@ 2026-09-15 0:13 ` Namjae Jeon
2026-09-15 14:29 ` Paulo Alcantara
1 sibling, 0 replies; 6+ messages in thread
From: Namjae Jeon @ 2026-09-15 0:13 UTC (permalink / raw)
To: Paulo Alcantara
Cc: linux-cifs, David Howells, Tom Talpey, Shyam Prasad N,
Ronnie Sahlberg, Bharath SM, stable
On Mon, Sep 14, 2026 at 10:10 AM Paulo Alcantara <pc@manguebit.org> wrote:
>
> wsl_to_fattr() mutates fattr fields as it parses each WSL EA. If
> validation later fails, the function returns false with partially
> mutated fattr fields that callers do not reset.
>
> Fix this by parsing into local variables and only committing them to
> fattr on success.
>
> Closes: https://sashiko.dev/#/patchset/20260906200517.725015-1-pc%40manguebit.org
> Fixes: 78e26bec4d6d ("smb: client: parse uid, gid, mode and dev from WSL reparse points")
> Signed-off-by: Paulo Alcantara <pc@manguebit.org>
> Cc: David Howells <dhowells@redhat.com>
> Cc: Tom Talpey <tom@talpey.com>
> Cc: Shyam Prasad N <sprasad@microsoft.com>
> Cc: Ronnie Sahlberg <ronniesahlberg@gmail.com>
> Cc: Bharath SM <bharathsm@microsoft.com>
> Cc: Namjae Jeon <linkinjeon@kernel.org>
> Cc: stable@vger.kernel.org
Reviewed-by: Namjae Jeon <linkinjeon@kernel.org>
Thanks!
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH 1/2] smb: client: fix unaligned access in WSL reparse point parser
2026-09-14 1:10 [PATCH 1/2] smb: client: fix unaligned access in WSL reparse point parser Paulo Alcantara
2026-09-14 1:10 ` [PATCH 2/2] smb: client: fix fattr leaking on wsl_to_fattr() failure Paulo Alcantara
2026-09-15 0:12 ` [PATCH 1/2] smb: client: fix unaligned access in WSL reparse point parser Namjae Jeon
@ 2026-09-15 14:29 ` Paulo Alcantara
2 siblings, 0 replies; 6+ messages in thread
From: Paulo Alcantara @ 2026-09-15 14:29 UTC (permalink / raw)
To: linux-cifs
Cc: David Howells, Tom Talpey, Shyam Prasad N, Ronnie Sahlberg,
Bharath SM, Namjae Jeon, stable
Paulo Alcantara <pc@manguebit.org> writes:
> When wsl_to_fattr() parses WSL extended attributes, it computes a
> payload pointer from ea->ea_data + ea_name_length + 1. Since the
> smb2_file_full_ea_info struct is __packed and all WSL xattr names are
> 6 bytes long, the value pointer always lands at an odd byte offset,
> never satisfying __le32 or __le64 alignment requirements.
>
> The code then casts this pointer to __le32 * or __le64 * and
> dereferences it directly, which may cause alignment faults on some
> architectures.
>
> Replace all such casts with get_unaligned_le32() and
> get_unaligned_le64() in reparse_mkdev(), wsl_make_kuid(),
> wsl_make_kgid() and wsl_to_fattr().
> ...
Applied.
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH 2/2] smb: client: fix fattr leaking on wsl_to_fattr() failure
2026-09-14 1:10 ` [PATCH 2/2] smb: client: fix fattr leaking on wsl_to_fattr() failure Paulo Alcantara
2026-09-15 0:13 ` Namjae Jeon
@ 2026-09-15 14:29 ` Paulo Alcantara
1 sibling, 0 replies; 6+ messages in thread
From: Paulo Alcantara @ 2026-09-15 14:29 UTC (permalink / raw)
To: linux-cifs
Cc: David Howells, Tom Talpey, Shyam Prasad N, Ronnie Sahlberg,
Bharath SM, Namjae Jeon, stable
Paulo Alcantara <pc@manguebit.org> writes:
> wsl_to_fattr() mutates fattr fields as it parses each WSL EA. If
> validation later fails, the function returns false with partially
> mutated fattr fields that callers do not reset.
>
> Fix this by parsing into local variables and only committing them to
> fattr on success.
> ...
Applied.
^ permalink raw reply [flat|nested] 6+ messages in thread
end of thread, other threads:[~2026-09-15 14:29 UTC | newest]
Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-14 1:10 [PATCH 1/2] smb: client: fix unaligned access in WSL reparse point parser Paulo Alcantara
2026-09-14 1:10 ` [PATCH 2/2] smb: client: fix fattr leaking on wsl_to_fattr() failure Paulo Alcantara
2026-09-15 0:13 ` Namjae Jeon
2026-09-15 14:29 ` Paulo Alcantara
2026-09-15 0:12 ` [PATCH 1/2] smb: client: fix unaligned access in WSL reparse point parser Namjae Jeon
2026-09-15 14:29 ` Paulo Alcantara
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox