Linux CIFS filesystem development
 help / color / mirror / Atom feed
* [PATCH v4 00/10] smb: client: fix OOB reads and UAFs in SMB2/3 receive paths
@ 2026-09-13 21:44 Frank Sorenson
  2026-09-13 21:44 ` [PATCH v4 01/10] smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs Frank Sorenson
                   ` (10 more replies)
  0 siblings, 11 replies; 17+ messages in thread
From: Frank Sorenson @ 2026-09-13 21:44 UTC (permalink / raw)
  To: linux-cifs, pc; +Cc: linkinjeon, ronniesahlberg, sprasad, tom, bharathsm

This series fixes ten bounds-checking defects in the SMB2/3 client,
all of which are reachable from a malicious or compromised server.

Patches 1-3 address the compound encrypted frame processing path:

Patch 1 fixes multiple pointer lifecycle and bounds-checking issues
in receive_encrypted_standard(), including a stale next_buffer pointer
that causes a UAF on error paths, and an integer overflow that allows
malformed trailing slices to bypass length checks.

Patch 2 adds a table of per-command minimum-response struct sizes,
used to reject responses too short for smb2_get_data_area_len() to
safely read command-specific struct fields.

Patch 3 fixes server->total_read tracking so that smb2_check_message()
validates against the actual per-sub-PDU size, rather than the full
remaining compound tail. Without this, a truncated non-last sub-PDU
could bypass the guards added in patch 2.

Note for stable: although patch 3 carries a Fixes: tag and Cc: stable,
I am not sure whether patch 2 should, since it adds a new table rather
than being a true fix. They are complementary: patch 3 supplies the
correct per-sub-PDU length that patch 2's guard consumes. Patch 3 is
safe on its own, but its computed length will not be checked against
the per-command minimum unless patch 2 is included as well.

The remaining patches fix lower-bound gaps and OOB reads in DFS referral
parsing, server interface list traversal, EA list traversal, posix SID
bounds, change-notify offset, snapshot enumeration, and SMB1 reparse
point validation.

The create-context patch carried through v3 as patch 11 has been dropped
from this series. Zihan Xi's recent series:

  [PATCH v3 0/2] smb: client: fix create context out-of-bounds reads
  https://lore.kernel.org/r/cover.1788516372.git.zihanx@nebusec.ai

covers the same defects, arrives with a PoC, and fixes
parse_query_id_ctxt() in a better way. Rather than post two
overlapping/competing fixes, I will help with reviewing and improving
that series instead. If it stalls, I'll re-post my version.

Testing compared cifs-next (7.2+) with and without this patchset:

samba - v3.1.1, v3.1.1+sign, v3.1.1+seal, v2.1, v2.1+sign, v1:
  - no new failures attributable to this series.
  - found netfs bug causing generic/759 with signing to fail
    (resolved by David Howells--now succeeds).

Windows Server 2022 - v3.1.1, v3.1.1+sign, v3.1.1+seal,
  v3.1.1+multichannel:
  - no failures.

v4 changes:
 - patch 2: dropped the smb2_check_min_pdu_len_table() BUILD_BUG_ON helper.
 - dropped patch 11 ("smb: client: fix OOB reads in smb2_parse_contexts()")
   in favor of Zihan Xi's series, as described above.
 - patch 9: corrected a bogus Fixes: tag. Explained bound choice of
   sizeof(struct smb_snapshot_array) vs the 16-byte MIN_SNAPSHOT_ARRAY_SIZE
   of MS-SMB2 3.3.5.15.1.
 - testing details
 - commit subjects and messages tightened throughout.

v3 changes:
 https://lore.kernel.org/linux-cifs/20260826153147.4112943-1-sorenson@redhat.com
 - respin entire series

v2 changes:
 - patch 6: reject next_entry_offset values that leave fewer than
   sizeof(*src) bytes remaining after advancing.

Frank Sorenson (10):
  smb: client: fix next_buffer UAF and NextCommand bounds in compound
    PDUs
  smb: client: validate minimum PDU size before smb2_get_data_area_len()
  smb: client: fix server->total_read for compound encrypted PDUs
  smb: client: fix missing lower-bound check on DFS referral string
    offsets
  smb: client: reject short Next offsets in parse_server_interfaces()
  smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs()
  smb: client: fix missing iov bounds check in parse_posix_sids()
  smb: client: fix underflow in is_valid_oplock_break() notify offset
    check
  smb: client: fix potential OOB read in smb3_enum_snapshots()
  smb: client: fix reparse buffer bounds in cifs_query_reparse_point()

 fs/smb/client/cifssmb.c   |  2 +-
 fs/smb/client/misc.c      | 12 +++++++--
 fs/smb/client/smb1misc.c  |  3 ++-
 fs/smb/client/smb2inode.c | 11 +++++++++
 fs/smb/client/smb2misc.c  | 40 ++++++++++++++++++++++++++++++
 fs/smb/client/smb2ops.c   | 51 +++++++++++++++++++++++++++++----------
 fs/smb/client/trace.h     |  1 +
 7 files changed, 103 insertions(+), 17 deletions(-)

-- 
2.55.0


^ permalink raw reply	[flat|nested] 17+ messages in thread

end of thread, other threads:[~2026-09-16 19:55 UTC | newest]

Thread overview: 17+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-13 21:44 [PATCH v4 00/10] smb: client: fix OOB reads and UAFs in SMB2/3 receive paths Frank Sorenson
2026-09-13 21:44 ` [PATCH v4 01/10] smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs Frank Sorenson
2026-09-13 21:45 ` [PATCH v4 02/10] smb: client: validate minimum PDU size before smb2_get_data_area_len() Frank Sorenson
2026-09-15 15:04   ` Paulo Alcantara
2026-09-15 16:41     ` Frank Sorenson
2026-09-16 14:22       ` Paulo Alcantara
2026-09-16 19:55         ` Frank Sorenson
2026-09-13 21:45 ` [PATCH v4 03/10] smb: client: fix server->total_read for compound encrypted PDUs Frank Sorenson
2026-09-13 21:45 ` [PATCH v4 04/10] smb: client: fix missing lower-bound check on DFS referral string offsets Frank Sorenson
2026-09-13 21:45 ` [PATCH v4 05/10] smb: client: reject short Next offsets in parse_server_interfaces() Frank Sorenson
2026-09-13 21:45 ` [PATCH v4 06/10] smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs() Frank Sorenson
2026-09-13 21:45 ` [PATCH v4 07/10] smb: client: fix missing iov bounds check in parse_posix_sids() Frank Sorenson
2026-09-13 21:45 ` [PATCH v4 08/10] smb: client: fix underflow in is_valid_oplock_break() notify offset check Frank Sorenson
2026-09-13 21:45 ` [PATCH v4 09/10] smb: client: fix potential OOB read in smb3_enum_snapshots() Frank Sorenson
2026-09-13 21:45 ` [PATCH v4 10/10] smb: client: fix reparse buffer bounds in cifs_query_reparse_point() Frank Sorenson
2026-09-14  1:08 ` [PATCH v4 00/10] smb: client: fix OOB reads and UAFs in SMB2/3 receive paths Frank Sorenson
2026-09-15 15:50   ` Paulo Alcantara

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox