From: Frank Sorenson <sorenson@redhat.com>
To: linux-cifs@vger.kernel.org, pc@manguebit.org
Cc: linkinjeon@kernel.org, ronniesahlberg@gmail.com,
sprasad@microsoft.com, tom@talpey.com, bharathsm@microsoft.com
Subject: [PATCH v5 0/9] smb: client: fix OOB reads and UAFs in SMB2/3 receive paths
Date: Wed, 16 Sep 2026 16:33:51 -0500 [thread overview]
Message-ID: <20260916213406.1496960-1-sorenson@redhat.com> (raw)
This series fixes nine bounds-checking defects in the SMB2/3 client,
all of which are reachable from a malicious or compromised server.
Patches 1-3 address the compound encrypted frame processing path:
Patch 1 fixes multiple pointer lifecycle and bounds-checking issues
in receive_encrypted_standard(), including a stale next_buffer pointer
that causes a UAF on error paths, and an integer overflow that allows
malformed trailing slices to bypass length checks.
Patch 2 replaces has_smb2_data_area[] with a table of per-command
minimum-response struct sizes, used to reject responses too short for
smb2_get_data_area_len() to safely read command-specific struct fields.
Patch 3 fixes server->total_read tracking so that smb2_check_message()
validates against the actual per-sub-PDU size, rather than the full
remaining compound tail. Without this, a truncated non-last sub-PDU
could bypass the guards added in patch 2.
Note for stable: although patch 3 carries a Fixes: tag and Cc: stable,
I am not sure whether patch 2 should, since it is hardening rather
than a fix for a specific regression.
The remaining patches fix lower-bound gaps and OOB reads in DFS referral
parsing, server interface list traversal, EA list traversal, posix SID
bounds, snapshot enumeration, and SMB1 reparse point validation.
The create-context patch carried through v3 as patch 11 has been dropped
from this series. Zihan Xi's recent series:
[PATCH v4 0/6] smb: client: fix create context out-of-bounds reads
https://lore.kernel.org/r/cover.1789478666.git.zihanx@nebusec.ai
covers the same defects, arrives with a PoC, and fixes
parse_query_id_ctxt() in a better way. Rather than post two
overlapping/competing fixes, I will help with reviewing and improving
that series instead. If it stalls, I'll re-post my version.
Testing compared cifs-next (7.3-rc2+) with and without this patchset:
samba - v3.1.1, v3.1.1+sign, v3.1.1+seal, v2.1, v2.1+sign, v1:
- no new failures attributable to this series.
- found netfs bug causing generic/759 with signing to fail
(resolved by David Howells--now succeeds).
Windows Server 2022 - v3.1.1, v3.1.1+sign, v3.1.1+seal,
v3.1.1+multichannel:
- no failures.
v5 changes:
- patch 2: replace the true/false indication of has_smb2_data_area[]
with smb2_min_pdu_len[], which indicates both presence of a data
area, and the size of it, if present
- patch 8: dropped; the new check could never be true
v4 changes:
https://lore.kernel.org/linux-cifs/20260913214510.3071370-1-sorenson@redhat.com
- patch 2: dropped the smb2_check_min_pdu_len_table() BUILD_BUG_ON helper.
- dropped patch 11
("smb: client: fix OOB reads in smb2_parse_contexts()")
in favor of Zihan Xi's series, as described above.
- patch 9: corrected a bogus Fixes: tag. Explained bound choice of
sizeof(struct smb_snapshot_array) vs the 16-byte MIN_SNAPSHOT_ARRAY_SIZE
of MS-SMB2 3.3.5.15.1.
- testing details: 7.2+ with samba & Windows Server 2022
- commit subjects and messages tightened throughout.
v3 changes:
https://lore.kernel.org/linux-cifs/20260826153147.4112943-1-sorenson@redhat.com
- respin entire series
v2 changes:
- patch 6: reject next_entry_offset values that leave fewer than
sizeof(*src) bytes remaining after advancing.
Frank Sorenson (9):
smb: client: fix next_buffer UAF and NextCommand bounds in compound
PDUs
smb: client: validate minimum PDU size before smb2_get_data_area_len()
smb: client: fix server->total_read for compound encrypted PDUs
smb: client: fix missing lower-bound check on DFS referral string
offsets
smb: client: reject short Next offsets in parse_server_interfaces()
smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs()
smb: client: fix missing iov bounds check in parse_posix_sids()
smb: client: fix potential OOB read in smb3_enum_snapshots()
smb: client: fix reparse buffer bounds in cifs_query_reparse_point()
fs/smb/client/cifssmb.c | 2 +-
fs/smb/client/misc.c | 12 +++++--
fs/smb/client/smb2inode.c | 11 +++++++
fs/smb/client/smb2misc.c | 69 +++++++++++++++++++++++----------------
fs/smb/client/smb2ops.c | 51 +++++++++++++++++++++--------
fs/smb/client/trace.h | 1 +
6 files changed, 102 insertions(+), 44 deletions(-)
--
2.55.0
next reply other threads:[~2026-09-16 21:34 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-16 21:33 Frank Sorenson [this message]
2026-09-16 21:33 ` [PATCH v5 1/9] smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs Frank Sorenson
2026-09-16 21:33 ` [PATCH v5 2/9] smb: client: validate minimum PDU size before smb2_get_data_area_len() Frank Sorenson
2026-09-16 21:33 ` [PATCH v5 3/9] smb: client: fix server->total_read for compound encrypted PDUs Frank Sorenson
2026-09-16 21:33 ` [PATCH v5 4/9] smb: client: fix missing lower-bound check on DFS referral string offsets Frank Sorenson
2026-09-16 21:33 ` [PATCH v5 5/9] smb: client: reject short Next offsets in parse_server_interfaces() Frank Sorenson
2026-09-16 21:33 ` [PATCH v5 6/9] smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs() Frank Sorenson
2026-09-16 21:33 ` [PATCH v5 7/9] smb: client: fix missing iov bounds check in parse_posix_sids() Frank Sorenson
2026-09-16 21:33 ` [PATCH v5 8/9] smb: client: fix potential OOB read in smb3_enum_snapshots() Frank Sorenson
2026-09-16 21:34 ` [PATCH v5 9/9] smb: client: fix reparse buffer bounds in cifs_query_reparse_point() Frank Sorenson
2026-09-17 18:15 ` [PATCH v5 0/9] smb: client: fix OOB reads and UAFs in SMB2/3 receive paths Paulo Alcantara
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260916213406.1496960-1-sorenson@redhat.com \
--to=sorenson@redhat.com \
--cc=bharathsm@microsoft.com \
--cc=linkinjeon@kernel.org \
--cc=linux-cifs@vger.kernel.org \
--cc=pc@manguebit.org \
--cc=ronniesahlberg@gmail.com \
--cc=sprasad@microsoft.com \
--cc=tom@talpey.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox