* [PATCH v5 0/9] smb: client: fix OOB reads and UAFs in SMB2/3 receive paths
@ 2026-09-16 21:33 Frank Sorenson
2026-09-16 21:33 ` [PATCH v5 1/9] smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs Frank Sorenson
` (9 more replies)
0 siblings, 10 replies; 11+ messages in thread
From: Frank Sorenson @ 2026-09-16 21:33 UTC (permalink / raw)
To: linux-cifs, pc; +Cc: linkinjeon, ronniesahlberg, sprasad, tom, bharathsm
This series fixes nine bounds-checking defects in the SMB2/3 client,
all of which are reachable from a malicious or compromised server.
Patches 1-3 address the compound encrypted frame processing path:
Patch 1 fixes multiple pointer lifecycle and bounds-checking issues
in receive_encrypted_standard(), including a stale next_buffer pointer
that causes a UAF on error paths, and an integer overflow that allows
malformed trailing slices to bypass length checks.
Patch 2 replaces has_smb2_data_area[] with a table of per-command
minimum-response struct sizes, used to reject responses too short for
smb2_get_data_area_len() to safely read command-specific struct fields.
Patch 3 fixes server->total_read tracking so that smb2_check_message()
validates against the actual per-sub-PDU size, rather than the full
remaining compound tail. Without this, a truncated non-last sub-PDU
could bypass the guards added in patch 2.
Note for stable: although patch 3 carries a Fixes: tag and Cc: stable,
I am not sure whether patch 2 should, since it is hardening rather
than a fix for a specific regression.
The remaining patches fix lower-bound gaps and OOB reads in DFS referral
parsing, server interface list traversal, EA list traversal, posix SID
bounds, snapshot enumeration, and SMB1 reparse point validation.
The create-context patch carried through v3 as patch 11 has been dropped
from this series. Zihan Xi's recent series:
[PATCH v4 0/6] smb: client: fix create context out-of-bounds reads
https://lore.kernel.org/r/cover.1789478666.git.zihanx@nebusec.ai
covers the same defects, arrives with a PoC, and fixes
parse_query_id_ctxt() in a better way. Rather than post two
overlapping/competing fixes, I will help with reviewing and improving
that series instead. If it stalls, I'll re-post my version.
Testing compared cifs-next (7.3-rc2+) with and without this patchset:
samba - v3.1.1, v3.1.1+sign, v3.1.1+seal, v2.1, v2.1+sign, v1:
- no new failures attributable to this series.
- found netfs bug causing generic/759 with signing to fail
(resolved by David Howells--now succeeds).
Windows Server 2022 - v3.1.1, v3.1.1+sign, v3.1.1+seal,
v3.1.1+multichannel:
- no failures.
v5 changes:
- patch 2: replace the true/false indication of has_smb2_data_area[]
with smb2_min_pdu_len[], which indicates both presence of a data
area, and the size of it, if present
- patch 8: dropped; the new check could never be true
v4 changes:
https://lore.kernel.org/linux-cifs/20260913214510.3071370-1-sorenson@redhat.com
- patch 2: dropped the smb2_check_min_pdu_len_table() BUILD_BUG_ON helper.
- dropped patch 11
("smb: client: fix OOB reads in smb2_parse_contexts()")
in favor of Zihan Xi's series, as described above.
- patch 9: corrected a bogus Fixes: tag. Explained bound choice of
sizeof(struct smb_snapshot_array) vs the 16-byte MIN_SNAPSHOT_ARRAY_SIZE
of MS-SMB2 3.3.5.15.1.
- testing details: 7.2+ with samba & Windows Server 2022
- commit subjects and messages tightened throughout.
v3 changes:
https://lore.kernel.org/linux-cifs/20260826153147.4112943-1-sorenson@redhat.com
- respin entire series
v2 changes:
- patch 6: reject next_entry_offset values that leave fewer than
sizeof(*src) bytes remaining after advancing.
Frank Sorenson (9):
smb: client: fix next_buffer UAF and NextCommand bounds in compound
PDUs
smb: client: validate minimum PDU size before smb2_get_data_area_len()
smb: client: fix server->total_read for compound encrypted PDUs
smb: client: fix missing lower-bound check on DFS referral string
offsets
smb: client: reject short Next offsets in parse_server_interfaces()
smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs()
smb: client: fix missing iov bounds check in parse_posix_sids()
smb: client: fix potential OOB read in smb3_enum_snapshots()
smb: client: fix reparse buffer bounds in cifs_query_reparse_point()
fs/smb/client/cifssmb.c | 2 +-
fs/smb/client/misc.c | 12 +++++--
fs/smb/client/smb2inode.c | 11 +++++++
fs/smb/client/smb2misc.c | 69 +++++++++++++++++++++++----------------
fs/smb/client/smb2ops.c | 51 +++++++++++++++++++++--------
fs/smb/client/trace.h | 1 +
6 files changed, 102 insertions(+), 44 deletions(-)
--
2.55.0
^ permalink raw reply [flat|nested] 11+ messages in thread
* [PATCH v5 1/9] smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
2026-09-16 21:33 [PATCH v5 0/9] smb: client: fix OOB reads and UAFs in SMB2/3 receive paths Frank Sorenson
@ 2026-09-16 21:33 ` Frank Sorenson
2026-09-16 21:33 ` [PATCH v5 2/9] smb: client: validate minimum PDU size before smb2_get_data_area_len() Frank Sorenson
` (8 subsequent siblings)
9 siblings, 0 replies; 11+ messages in thread
From: Frank Sorenson @ 2026-09-16 21:33 UTC (permalink / raw)
To: linux-cifs, pc
Cc: linkinjeon, ronniesahlberg, sprasad, tom, bharathsm, stable
Fix several related bounds checking and pointer lifecycle issues in
receive_encrypted_standard()'s handling of compound encrypted frames:
- Clear next_buffer after assigning it to server->bigbuf. A stale
next_buffer pointer can lead to a use-after-free on subsequent
error paths.
- Update pdu_length to the decrypted plaintext size (buf_size). Using
the pre-decryption length allows NextCommand to point into stale
ciphertext residue.
- Reject next_cmd values smaller than MID_HEADER_SIZE(server).
- Fix an integer overflow in the upper bound check by verifying
pdu_length - next_cmd < MID_HEADER_SIZE(server), ensuring the
trailing slice is large enough for a header.
Fixes: b24df3e30cbf ("cifs: update receive_encrypted_standard to handle compounded responses")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
---
fs/smb/client/smb2ops.c | 11 ++++++++++-
1 file changed, 10 insertions(+), 1 deletion(-)
diff --git a/fs/smb/client/smb2ops.c b/fs/smb/client/smb2ops.c
index cb4fd09f996e..fcf7033889c7 100644
--- a/fs/smb/client/smb2ops.c
+++ b/fs/smb/client/smb2ops.c
@@ -5365,6 +5365,7 @@ receive_encrypted_standard(struct TCP_Server_Info *server,
length = decrypt_raw_data(server, buf, buf_size, NULL, false);
if (length)
return length;
+ pdu_length = buf_size;
next_is_large = server->large_buf;
one_more:
@@ -5377,8 +5378,15 @@ receive_encrypted_standard(struct TCP_Server_Info *server,
}
if (next_cmd) {
- if (WARN_ON_ONCE(next_cmd > pdu_length))
+ if (next_cmd < MID_HEADER_SIZE(server) ||
+ next_cmd > pdu_length ||
+ pdu_length - next_cmd < MID_HEADER_SIZE(server)) {
+ unsigned int max_next = pdu_length > (unsigned int)MID_HEADER_SIZE(server) ?
+ pdu_length - (unsigned int)MID_HEADER_SIZE(server) : 0;
+ cifs_server_dbg(VFS, "invalid NextCommand offset %u out of range [%zu, %u]\n",
+ next_cmd, MID_HEADER_SIZE(server), max_next);
return -1;
+ }
if (next_is_large)
next_buffer = (char *)cifs_buf_get();
else
@@ -5414,6 +5422,7 @@ receive_encrypted_standard(struct TCP_Server_Info *server,
server->bigbuf = buf = next_buffer;
else
server->smallbuf = buf = next_buffer;
+ next_buffer = NULL;
goto one_more;
} else if (ret != 0) {
/*
--
2.55.0
^ permalink raw reply related [flat|nested] 11+ messages in thread
* [PATCH v5 2/9] smb: client: validate minimum PDU size before smb2_get_data_area_len()
2026-09-16 21:33 [PATCH v5 0/9] smb: client: fix OOB reads and UAFs in SMB2/3 receive paths Frank Sorenson
2026-09-16 21:33 ` [PATCH v5 1/9] smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs Frank Sorenson
@ 2026-09-16 21:33 ` Frank Sorenson
2026-09-16 21:33 ` [PATCH v5 3/9] smb: client: fix server->total_read for compound encrypted PDUs Frank Sorenson
` (7 subsequent siblings)
9 siblings, 0 replies; 11+ messages in thread
From: Frank Sorenson @ 2026-09-16 21:33 UTC (permalink / raw)
To: linux-cifs, pc; +Cc: linkinjeon, ronniesahlberg, sprasad, tom, bharathsm
__smb2_calc_size() calls smb2_get_data_area_len(), which reads
command-specific struct fields to locate the data area. However,
smb2_check_message() only validates StructureSize2, meaning a truncated
response could cause smb2_get_data_area_len() to read out-of-bounds.
Replace has_smb2_data_area[] with smb2_min_pdu_len[], which is now
used to indicate both whether a command's response has a data area
and the size of that fixed response struct. A non-zero entry means
the command has a data area, and is the minimum length required
before the struct is read.
For each command with a data area, PDUs shorter than this minimum size
are rejected instead of parsed.
The minimum is not applied to SMB2 error responses, which carry only
the 9-byte error body, the same exemption the StructureSize2 check
above it already makes. STATUS_MORE_PROCESSING_REQUIRED is
treated as a normal reply, since an in-progress SESSION_SETUP
response carries a full body and a security blob.
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
---
fs/smb/client/smb2misc.c | 69 ++++++++++++++++++++++++----------------
1 file changed, 41 insertions(+), 28 deletions(-)
diff --git a/fs/smb/client/smb2misc.c b/fs/smb/client/smb2misc.c
index 9068175e57cd..0cfe60ae42c3 100644
--- a/fs/smb/client/smb2misc.c
+++ b/fs/smb/client/smb2misc.c
@@ -85,6 +85,36 @@ static const __le16 smb2_rsp_struct_sizes[NUMBER_OF_SMB2_COMMANDS] = {
/* SMB2_OPLOCK_BREAK */ cpu_to_le16(24)
};
+/*
+ * Minimum received PDU size for commands whose response carries a
+ * variable-length data area. A non-zero entry marks the command as
+ * having one, and gives the length smb2_check_message() requires
+ * before smb2_get_data_area_len() reads the offset and length fields
+ * out of the fixed response struct.
+ */
+static const size_t smb2_min_pdu_len[NUMBER_OF_SMB2_COMMANDS] = {
+ /* SMB2_NEGOTIATE */ sizeof(struct smb2_negotiate_rsp),
+ /* SMB2_SESSION_SETUP */ sizeof(struct smb2_sess_setup_rsp),
+ /* SMB2_LOGOFF */ 0,
+ /* SMB2_TREE_CONNECT */ 0,
+ /* SMB2_TREE_DISCONNECT */ 0,
+ /* SMB2_CREATE */ sizeof(struct smb2_create_rsp),
+ /* SMB2_CLOSE */ 0,
+ /* SMB2_FLUSH */ 0,
+ /* SMB2_READ */ sizeof(struct smb2_read_rsp),
+ /* SMB2_WRITE */ 0,
+ /* SMB2_LOCK */ 0,
+ /* SMB2_IOCTL */ sizeof(struct smb2_ioctl_rsp),
+ /* SMB2_CANCEL */ 0,
+ /* SMB2_ECHO */ 0,
+ /* SMB2_QUERY_DIRECTORY */ sizeof(struct smb2_query_directory_rsp),
+ /* SMB2_CHANGE_NOTIFY */ sizeof(struct smb2_change_notify_rsp),
+ /* SMB2_QUERY_INFO */ sizeof(struct smb2_query_info_rsp),
+ /* SMB2_SET_INFO */ 0,
+ /* SMB2_OPLOCK_BREAK */ 0,
+};
+
+#define smb2_has_data_area(cmd) (smb2_min_pdu_len[cmd] != 0)
#define SMB311_NEGPROT_BASE_SIZE (sizeof(struct smb2_hdr) + sizeof(struct smb2_negotiate_rsp))
static __u32 get_neg_ctxt_len(struct smb2_hdr *hdr, __u32 len,
@@ -233,6 +263,16 @@ smb2_check_message(char *buf, unsigned int pdu_len, unsigned int len,
}
}
+ if ((shdr->Status == STATUS_SUCCESS ||
+ shdr->Status == STATUS_MORE_PROCESSING_REQUIRED ||
+ pdu->StructureSize2 != SMB2_ERROR_STRUCTURE_SIZE2_LE) &&
+ smb2_has_data_area(command) &&
+ len < smb2_min_pdu_len[command]) {
+ cifs_server_dbg(VFS, "SMB2 command %d response too short: %u < %zu\n",
+ command, len, smb2_min_pdu_len[command]);
+ return 1;
+ }
+
have_data = false;
data_area_overlap = false;
calc_len = __smb2_calc_size(buf, &have_data, &data_area_overlap);
@@ -298,33 +338,6 @@ smb2_check_message(char *buf, unsigned int pdu_len, unsigned int len,
return 0;
}
-/*
- * The size of the variable area depends on the offset and length fields
- * located in different fields for various SMB2 responses. SMB2 responses
- * with no variable length info, show an offset of zero for the offset field.
- */
-static const bool has_smb2_data_area[NUMBER_OF_SMB2_COMMANDS] = {
- /* SMB2_NEGOTIATE */ true,
- /* SMB2_SESSION_SETUP */ true,
- /* SMB2_LOGOFF */ false,
- /* SMB2_TREE_CONNECT */ false,
- /* SMB2_TREE_DISCONNECT */ false,
- /* SMB2_CREATE */ true,
- /* SMB2_CLOSE */ false,
- /* SMB2_FLUSH */ false,
- /* SMB2_READ */ true,
- /* SMB2_WRITE */ false,
- /* SMB2_LOCK */ false,
- /* SMB2_IOCTL */ true,
- /* SMB2_CANCEL */ false, /* BB CHECK this not listed in documentation */
- /* SMB2_ECHO */ false,
- /* SMB2_QUERY_DIRECTORY */ true,
- /* SMB2_CHANGE_NOTIFY */ true,
- /* SMB2_QUERY_INFO */ true,
- /* SMB2_SET_INFO */ false,
- /* SMB2_OPLOCK_BREAK */ false
-};
-
/*
* Returns the pointer to the beginning of the data area. Length of the data
* area and the offset to it (from the beginning of the smb are also returned.
@@ -451,7 +464,7 @@ __smb2_calc_size(void *buf, bool *have_data, bool *data_area_overlap)
*/
len += le16_to_cpu(pdu->StructureSize2);
- if (has_smb2_data_area[le16_to_cpu(shdr->Command)] == false)
+ if (!smb2_has_data_area(le16_to_cpu(shdr->Command)))
goto calc_size_exit;
smb2_get_data_area_len(&offset, &data_length, shdr);
--
2.55.0
^ permalink raw reply related [flat|nested] 11+ messages in thread
* [PATCH v5 3/9] smb: client: fix server->total_read for compound encrypted PDUs
2026-09-16 21:33 [PATCH v5 0/9] smb: client: fix OOB reads and UAFs in SMB2/3 receive paths Frank Sorenson
2026-09-16 21:33 ` [PATCH v5 1/9] smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs Frank Sorenson
2026-09-16 21:33 ` [PATCH v5 2/9] smb: client: validate minimum PDU size before smb2_get_data_area_len() Frank Sorenson
@ 2026-09-16 21:33 ` Frank Sorenson
2026-09-16 21:33 ` [PATCH v5 4/9] smb: client: fix missing lower-bound check on DFS referral string offsets Frank Sorenson
` (6 subsequent siblings)
9 siblings, 0 replies; 11+ messages in thread
From: Frank Sorenson @ 2026-09-16 21:33 UTC (permalink / raw)
To: linux-cifs, pc
Cc: linkinjeon, ronniesahlberg, sprasad, tom, bharathsm, stable
In receive_encrypted_standard(), server->total_read is left at the
full decrypted frame size when walking sub-PDUs of a compound encrypted
frame. As a result, cifs_handle_standard() passes this full size
to smb2_check_message(), causing the PDU length guards to incorrectly
validate the entire compound frame instead of the current sub-PDU.
This allows truncated non-last sub-PDUs to bypass length validation,
leading to out-of-bounds reads in smb2_get_data_area_len().
Fix this by setting server->total_read to the true length of the
current sub-PDU: next_cmd for non-last sub-PDUs, and the remaining
pdu_length for the last one.
Fixes: b24df3e30cbf ("cifs: update receive_encrypted_standard to handle compounded responses")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
---
fs/smb/client/smb2ops.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/fs/smb/client/smb2ops.c b/fs/smb/client/smb2ops.c
index fcf7033889c7..7f2177f6fc01 100644
--- a/fs/smb/client/smb2ops.c
+++ b/fs/smb/client/smb2ops.c
@@ -5371,6 +5371,7 @@ receive_encrypted_standard(struct TCP_Server_Info *server,
one_more:
shdr = (struct smb2_hdr *)buf;
next_cmd = le32_to_cpu(shdr->NextCommand);
+ server->total_read = next_cmd ? next_cmd : pdu_length;
if (*num_mids >= MAX_COMPOUND) {
cifs_server_dbg(VFS, "too many PDUs in compound\n");
--
2.55.0
^ permalink raw reply related [flat|nested] 11+ messages in thread
* [PATCH v5 4/9] smb: client: fix missing lower-bound check on DFS referral string offsets
2026-09-16 21:33 [PATCH v5 0/9] smb: client: fix OOB reads and UAFs in SMB2/3 receive paths Frank Sorenson
` (2 preceding siblings ...)
2026-09-16 21:33 ` [PATCH v5 3/9] smb: client: fix server->total_read for compound encrypted PDUs Frank Sorenson
@ 2026-09-16 21:33 ` Frank Sorenson
2026-09-16 21:33 ` [PATCH v5 5/9] smb: client: reject short Next offsets in parse_server_interfaces() Frank Sorenson
` (5 subsequent siblings)
9 siblings, 0 replies; 11+ messages in thread
From: Frank Sorenson @ 2026-09-16 21:33 UTC (permalink / raw)
To: linux-cifs, pc
Cc: linkinjeon, ronniesahlberg, sprasad, tom, bharathsm, stable
parse_dfs_referrals() checks that DfsPathOffset and NetworkAddressOffset
do not exceed the buffer end, but fails to check that they don't point
inside the referral header itself.
If a server provides an offset smaller than
sizeof(struct dfs_referral_level_3), the derived string pointer overlaps
with the struct fields, causing cifs_strndup_from_utf16() to interpret
header data as UTF-16 strings.
Fix this by enforcing that string offsets are at least sizeof(*ref).
Fixes: 4ecce920e13a ("CIFS: move DFS response parsing out of SMB1 code")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
---
fs/smb/client/misc.c | 12 ++++++++++--
1 file changed, 10 insertions(+), 2 deletions(-)
diff --git a/fs/smb/client/misc.c b/fs/smb/client/misc.c
index 945194fe7a97..05168284f205 100644
--- a/fs/smb/client/misc.c
+++ b/fs/smb/client/misc.c
@@ -788,7 +788,11 @@ parse_dfs_referrals(struct get_dfs_referral_rsp *rsp, u32 rsp_size,
node->ref_flag = le16_to_cpu(ref->ReferralEntryFlags);
/* copy DfsPath */
- if (le16_to_cpu(ref->DfsPathOffset) > data_end - (char *)ref) {
+ if (le16_to_cpu(ref->DfsPathOffset) < sizeof(*ref) ||
+ le16_to_cpu(ref->DfsPathOffset) > data_end - (char *)ref) {
+ cifs_dbg(VFS, "%s: DfsPathOffset %u out of range [%zu, %td]\n",
+ __func__, le16_to_cpu(ref->DfsPathOffset),
+ sizeof(*ref), data_end - (char *)ref);
rc = -EINVAL;
goto parse_DFS_referrals_exit;
}
@@ -802,7 +806,11 @@ parse_dfs_referrals(struct get_dfs_referral_rsp *rsp, u32 rsp_size,
}
/* copy link target UNC */
- if (le16_to_cpu(ref->NetworkAddressOffset) > data_end - (char *)ref) {
+ if (le16_to_cpu(ref->NetworkAddressOffset) < sizeof(*ref) ||
+ le16_to_cpu(ref->NetworkAddressOffset) > data_end - (char *)ref) {
+ cifs_dbg(VFS, "%s: NetworkAddressOffset %u out of range [%zu, %td]\n",
+ __func__, le16_to_cpu(ref->NetworkAddressOffset),
+ sizeof(*ref), data_end - (char *)ref);
rc = -EINVAL;
goto parse_DFS_referrals_exit;
}
--
2.55.0
^ permalink raw reply related [flat|nested] 11+ messages in thread
* [PATCH v5 5/9] smb: client: reject short Next offsets in parse_server_interfaces()
2026-09-16 21:33 [PATCH v5 0/9] smb: client: fix OOB reads and UAFs in SMB2/3 receive paths Frank Sorenson
` (3 preceding siblings ...)
2026-09-16 21:33 ` [PATCH v5 4/9] smb: client: fix missing lower-bound check on DFS referral string offsets Frank Sorenson
@ 2026-09-16 21:33 ` Frank Sorenson
2026-09-16 21:33 ` [PATCH v5 6/9] smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs() Frank Sorenson
` (4 subsequent siblings)
9 siblings, 0 replies; 11+ messages in thread
From: Frank Sorenson @ 2026-09-16 21:33 UTC (permalink / raw)
To: linux-cifs, pc
Cc: linkinjeon, ronniesahlberg, sprasad, tom, bharathsm, stable
In parse_server_interfaces(), the server-supplied Next offset is
validated against bytes_left, but not against the size of the interface
structure itself.
A small, non-zero Next value can pass the bounds check but advance the
pointer by less than sizeof(*p). This causes the next iteration of the
loop to read misaligned, overlapping structure fields.
Fix this by ensuring the Next offset is at least sizeof(*p).
Fixes: 7d34ec36abb8 ("smb3: fix for slab out of bounds on mount to ksmbd")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
---
fs/smb/client/smb2ops.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/fs/smb/client/smb2ops.c b/fs/smb/client/smb2ops.c
index 7f2177f6fc01..bda940cb3784 100644
--- a/fs/smb/client/smb2ops.c
+++ b/fs/smb/client/smb2ops.c
@@ -785,9 +785,9 @@ parse_server_interfaces(struct network_interface_info_ioctl_rsp *buf,
break;
}
/* Validate that Next doesn't point beyond the buffer */
- if (next > bytes_left) {
- cifs_dbg(VFS, "%s: invalid Next pointer %zu > %zd\n",
- __func__, next, bytes_left);
+ if (next < sizeof(*p) || next > bytes_left) {
+ cifs_dbg(VFS, "%s: invalid Next pointer %zu out of range [%zu, %zd]\n",
+ __func__, next, sizeof(*p), bytes_left);
rc = -EINVAL;
goto out;
}
--
2.55.0
^ permalink raw reply related [flat|nested] 11+ messages in thread
* [PATCH v5 6/9] smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs()
2026-09-16 21:33 [PATCH v5 0/9] smb: client: fix OOB reads and UAFs in SMB2/3 receive paths Frank Sorenson
` (4 preceding siblings ...)
2026-09-16 21:33 ` [PATCH v5 5/9] smb: client: reject short Next offsets in parse_server_interfaces() Frank Sorenson
@ 2026-09-16 21:33 ` Frank Sorenson
2026-09-16 21:33 ` [PATCH v5 7/9] smb: client: fix missing iov bounds check in parse_posix_sids() Frank Sorenson
` (3 subsequent siblings)
9 siblings, 0 replies; 11+ messages in thread
From: Frank Sorenson @ 2026-09-16 21:33 UTC (permalink / raw)
To: linux-cifs, pc
Cc: linkinjeon, ronniesahlberg, sprasad, tom, bharathsm, stable
In move_smb2_ea_to_cifs(), the while (src_size > 0) loop condition is
insufficient. It allows iteration to continue even if the remaining
src_size is too small to contain a complete smb2_ea_info structure.
Consequently, reads of ea_name_length and ea_value_length can occur
out-of-bounds.
Fix this by ensuring src_size >= sizeof(*src) before attempting to read
any structure fields. Additionally, reject any next_entry_offset that is
smaller than sizeof(*src) or that would advance the pointer beyond the
available buffer.
Note that for calls where the server returns a malformed EA list, the
error returned to userspace changes from -ENODATA (getxattr) or
-ERANGE (listxattr) to -EIO. This correctly signals a server protocol
error rather than misleadingly indicating "attribute not present" or
"output buffer too small".
Fixes: 95907fea4fd8 ("cifs: Add support for reading attributes on SMB2+")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
---
fs/smb/client/smb2ops.c | 25 +++++++++++++++++--------
fs/smb/client/trace.h | 1 +
2 files changed, 18 insertions(+), 8 deletions(-)
diff --git a/fs/smb/client/smb2ops.c b/fs/smb/client/smb2ops.c
index bda940cb3784..ee3c98e3f316 100644
--- a/fs/smb/client/smb2ops.c
+++ b/fs/smb/client/smb2ops.c
@@ -1053,8 +1053,9 @@ move_smb2_ea_to_cifs(char *dst, size_t dst_size,
char *name, *value;
size_t buf_size = dst_size;
size_t name_len, value_len, user_name_len;
+ u32 next_off;
- while (src_size > 0) {
+ while (src_size >= sizeof(*src)) {
name_len = (size_t)src->ea_name_length;
value_len = (size_t)le16_to_cpu(src->ea_value_length);
@@ -1110,14 +1111,22 @@ move_smb2_ea_to_cifs(char *dst, size_t dst_size,
if (!src->next_entry_offset)
break;
- if (src_size < le32_to_cpu(src->next_entry_offset)) {
- /* stop before overrun buffer */
- rc = -ERANGE;
- break;
+ next_off = le32_to_cpu(src->next_entry_offset);
+ if (next_off < sizeof(*src) || src_size < next_off) {
+ cifs_dbg(FYI, "EA next_entry_offset %u out of range [%zu, %zu]\n",
+ next_off, sizeof(*src), src_size);
+ rc = smb_EIO2(smb_eio_trace_ea_next_offset,
+ next_off, src_size);
+ goto out;
+ }
+ src_size -= next_off;
+ src = (void *)((char *)src + next_off);
+ if (src_size > 0 && src_size < sizeof(*src)) {
+ cifs_dbg(FYI, "EA next_entry_offset %u left truncated entry (%zu bytes)\n",
+ next_off, src_size);
+ rc = smb_EIO2(smb_eio_trace_ea_next_offset, next_off, src_size);
+ goto out;
}
- src_size -= le32_to_cpu(src->next_entry_offset);
- src = (void *)((char *)src +
- le32_to_cpu(src->next_entry_offset));
}
/* didn't find the named attribute */
diff --git a/fs/smb/client/trace.h b/fs/smb/client/trace.h
index b442cccd1530..bb8d0197cb54 100644
--- a/fs/smb/client/trace.h
+++ b/fs/smb/client/trace.h
@@ -27,6 +27,7 @@
EM(smb_eio_trace_copychunk_overcopy_c, "copychunk_overcopy_c") \
EM(smb_eio_trace_create_rsp_too_small, "create_rsp_too_small") \
EM(smb_eio_trace_dfsref_no_rsp, "dfsref_no_rsp") \
+ EM(smb_eio_trace_ea_next_offset, "ea_next_offset") \
EM(smb_eio_trace_ea_overrun, "ea_overrun") \
EM(smb_eio_trace_extract_will_pin, "extract_will_pin") \
EM(smb_eio_trace_forced_shutdown, "forced_shutdown") \
--
2.55.0
^ permalink raw reply related [flat|nested] 11+ messages in thread
* [PATCH v5 7/9] smb: client: fix missing iov bounds check in parse_posix_sids()
2026-09-16 21:33 [PATCH v5 0/9] smb: client: fix OOB reads and UAFs in SMB2/3 receive paths Frank Sorenson
` (5 preceding siblings ...)
2026-09-16 21:33 ` [PATCH v5 6/9] smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs() Frank Sorenson
@ 2026-09-16 21:33 ` Frank Sorenson
2026-09-16 21:33 ` [PATCH v5 8/9] smb: client: fix potential OOB read in smb3_enum_snapshots() Frank Sorenson
` (2 subsequent siblings)
9 siblings, 0 replies; 11+ messages in thread
From: Frank Sorenson @ 2026-09-16 21:33 UTC (permalink / raw)
To: linux-cifs, pc
Cc: linkinjeon, ronniesahlberg, sprasad, tom, bharathsm, stable
In parse_posix_sids(), sidsbuf_end is calculated using the server-supplied
out_len without being validated against the actual length of the received
iov (iov_len).
If a server provides an inflated out_len, sidsbuf_end will point past the
end of the iov. This defeats the bounds guards in posix_info_sid_size(),
allowing out-of-bounds reads into adjacent kernel memory.
Fix this by rejecting responses where the calculated sidsbuf_end would
exceed the received iov boundaries or cause pointer wraparound.
Fixes: a90f37e3d7ac ("smb: client: parse owner/group when creating reparse points")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
---
fs/smb/client/smb2inode.c | 11 +++++++++++
1 file changed, 11 insertions(+)
diff --git a/fs/smb/client/smb2inode.c b/fs/smb/client/smb2inode.c
index 96063e355186..13fe8e3b48f3 100644
--- a/fs/smb/client/smb2inode.c
+++ b/fs/smb/client/smb2inode.c
@@ -77,6 +77,17 @@ static int parse_posix_sids(struct cifs_open_info_data *data,
sidsbuf = (u8 *)qi + le16_to_cpu(qi->OutputBufferOffset) + qi_len;
sidsbuf_end = sidsbuf + out_len - qi_len;
+ if (sidsbuf_end < sidsbuf) {
+ cifs_dbg(VFS, "%s: server-supplied out_len %u caused pointer wraparound\n",
+ __func__, out_len);
+ return -EINVAL;
+ }
+ if (sidsbuf_end > (u8 *)rsp_iov->iov_base + rsp_iov->iov_len) {
+ cifs_dbg(VFS, "%s: server-supplied out_len %u overruns iov by %td bytes\n",
+ __func__, out_len,
+ sidsbuf_end - ((u8 *)rsp_iov->iov_base + rsp_iov->iov_len));
+ return -EINVAL;
+ }
owner_len = posix_info_sid_size(sidsbuf, sidsbuf_end);
if (owner_len == -1)
--
2.55.0
^ permalink raw reply related [flat|nested] 11+ messages in thread
* [PATCH v5 8/9] smb: client: fix potential OOB read in smb3_enum_snapshots()
2026-09-16 21:33 [PATCH v5 0/9] smb: client: fix OOB reads and UAFs in SMB2/3 receive paths Frank Sorenson
` (6 preceding siblings ...)
2026-09-16 21:33 ` [PATCH v5 7/9] smb: client: fix missing iov bounds check in parse_posix_sids() Frank Sorenson
@ 2026-09-16 21:33 ` Frank Sorenson
2026-09-16 21:34 ` [PATCH v5 9/9] smb: client: fix reparse buffer bounds in cifs_query_reparse_point() Frank Sorenson
2026-09-17 18:15 ` [PATCH v5 0/9] smb: client: fix OOB reads and UAFs in SMB2/3 receive paths Paulo Alcantara
9 siblings, 0 replies; 11+ messages in thread
From: Frank Sorenson @ 2026-09-16 21:33 UTC (permalink / raw)
To: linux-cifs, pc
Cc: linkinjeon, ronniesahlberg, sprasad, tom, bharathsm, stable
If snapshot_array_size is smaller than GMT_TOKEN_SIZE,
smb3_enum_snapshots() sets ret_data_len to
sizeof(struct smb_snapshot_array) without verifying the actual length
of the server's reply.
Because SMB2_ioctl() places no lower bound on the server-supplied
OutputCount and allocates retbuf to exactly that length, a short reply
results in ret_data_len exceeding the size of retbuf. The subsequent
copy_to_user() then reads past the end of retbuf, leaking adjacent slab
memory to userspace. The subsequent clamp check is ineffective as it
only reduces ret_data_len.
Fix this by rejecting replies shorter than
sizeof(struct smb_snapshot_array) with -EIO. Note that the bound is set
to the 12-byte struct size rather than the 16-byte
MIN_SNAPSHOT_ARRAY_SIZE defined in MS-SMB2 3.3.5.15.1, because 12 bytes
is exactly what copy_to_user() attempts to read.
Fixes: e02789a53d71 ("smb3: enumerating snapshots was leaving part of the data off end")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
---
fs/smb/client/smb2ops.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
diff --git a/fs/smb/client/smb2ops.c b/fs/smb/client/smb2ops.c
index ee3c98e3f316..3464470d3297 100644
--- a/fs/smb/client/smb2ops.c
+++ b/fs/smb/client/smb2ops.c
@@ -2463,8 +2463,14 @@ smb3_enum_snapshots(const unsigned int xid, struct cifs_tcon *tcon,
* and retry the ioctl again with larger array size sufficient
* to hold all of the snapshot GMT tokens on the second try.
*/
- if (snapshot_in.snapshot_array_size < GMT_TOKEN_SIZE)
+ if (snapshot_in.snapshot_array_size < GMT_TOKEN_SIZE) {
+ if (ret_data_len < sizeof(struct smb_snapshot_array)) {
+ rc = -EIO;
+ kfree(retbuf);
+ return rc;
+ }
ret_data_len = sizeof(struct smb_snapshot_array);
+ }
/*
* We return struct SRV_SNAPSHOT_ARRAY, followed by
--
2.55.0
^ permalink raw reply related [flat|nested] 11+ messages in thread
* [PATCH v5 9/9] smb: client: fix reparse buffer bounds in cifs_query_reparse_point()
2026-09-16 21:33 [PATCH v5 0/9] smb: client: fix OOB reads and UAFs in SMB2/3 receive paths Frank Sorenson
` (7 preceding siblings ...)
2026-09-16 21:33 ` [PATCH v5 8/9] smb: client: fix potential OOB read in smb3_enum_snapshots() Frank Sorenson
@ 2026-09-16 21:34 ` Frank Sorenson
2026-09-17 18:15 ` [PATCH v5 0/9] smb: client: fix OOB reads and UAFs in SMB2/3 receive paths Paulo Alcantara
9 siblings, 0 replies; 11+ messages in thread
From: Frank Sorenson @ 2026-09-16 21:34 UTC (permalink / raw)
To: linux-cifs, pc
Cc: linkinjeon, ronniesahlberg, sprasad, tom, bharathsm, stable
In cifs_query_reparse_point(), the start >= end check before casting to
struct reparse_data_buffer * only ensures the start pointer is within the
response. It fails to verify that there is enough space remaining for the
fixed 8-byte header of the structure.
If a server provides a DataOffset that leaves less than 8 bytes remaining,
the check passes, but subsequent reads of ReparseTag and ReparseDataLength
will occur out-of-bounds.
Fix this by ensuring the remaining space is at least the size of the
reparse_data_buffer structure before accessing its fields.
Fixes: c13b779d26b3 ("cifs: Fix validation of SMB1 query reparse point response")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
---
fs/smb/client/cifssmb.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/fs/smb/client/cifssmb.c b/fs/smb/client/cifssmb.c
index f9aff0712794..6dddbd84b93b 100644
--- a/fs/smb/client/cifssmb.c
+++ b/fs/smb/client/cifssmb.c
@@ -3080,7 +3080,7 @@ int cifs_query_reparse_point(const unsigned int xid,
end = 2 + get_bcc(&io_rsp->hdr) + (__u8 *)&io_rsp->ByteCount;
start = (__u8 *)&io_rsp->hdr.Protocol + data_offset;
- if (start >= end) {
+ if (start >= end || (size_t)(end - start) < sizeof(*buf)) {
rc = smb_EIO2(smb_eio_trace_qreparse_data_area,
(unsigned long)start - (unsigned long)io_rsp,
(unsigned long)end - (unsigned long)io_rsp);
--
2.55.0
^ permalink raw reply related [flat|nested] 11+ messages in thread
* Re: [PATCH v5 0/9] smb: client: fix OOB reads and UAFs in SMB2/3 receive paths
2026-09-16 21:33 [PATCH v5 0/9] smb: client: fix OOB reads and UAFs in SMB2/3 receive paths Frank Sorenson
` (8 preceding siblings ...)
2026-09-16 21:34 ` [PATCH v5 9/9] smb: client: fix reparse buffer bounds in cifs_query_reparse_point() Frank Sorenson
@ 2026-09-17 18:15 ` Paulo Alcantara
9 siblings, 0 replies; 11+ messages in thread
From: Paulo Alcantara @ 2026-09-17 18:15 UTC (permalink / raw)
To: Frank Sorenson, linux-cifs
Cc: linkinjeon, ronniesahlberg, sprasad, tom, bharathsm
Frank Sorenson <sorenson@redhat.com> writes:
> This series fixes nine bounds-checking defects in the SMB2/3 client,
> all of which are reachable from a malicious or compromised server.
> ...
Applied.
BTW, The Fixes: tag in patch 9/9 was referring to a wrong commit id, so
I fixed it.
^ permalink raw reply [flat|nested] 11+ messages in thread
end of thread, other threads:[~2026-09-17 18:15 UTC | newest]
Thread overview: 11+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-16 21:33 [PATCH v5 0/9] smb: client: fix OOB reads and UAFs in SMB2/3 receive paths Frank Sorenson
2026-09-16 21:33 ` [PATCH v5 1/9] smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs Frank Sorenson
2026-09-16 21:33 ` [PATCH v5 2/9] smb: client: validate minimum PDU size before smb2_get_data_area_len() Frank Sorenson
2026-09-16 21:33 ` [PATCH v5 3/9] smb: client: fix server->total_read for compound encrypted PDUs Frank Sorenson
2026-09-16 21:33 ` [PATCH v5 4/9] smb: client: fix missing lower-bound check on DFS referral string offsets Frank Sorenson
2026-09-16 21:33 ` [PATCH v5 5/9] smb: client: reject short Next offsets in parse_server_interfaces() Frank Sorenson
2026-09-16 21:33 ` [PATCH v5 6/9] smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs() Frank Sorenson
2026-09-16 21:33 ` [PATCH v5 7/9] smb: client: fix missing iov bounds check in parse_posix_sids() Frank Sorenson
2026-09-16 21:33 ` [PATCH v5 8/9] smb: client: fix potential OOB read in smb3_enum_snapshots() Frank Sorenson
2026-09-16 21:34 ` [PATCH v5 9/9] smb: client: fix reparse buffer bounds in cifs_query_reparse_point() Frank Sorenson
2026-09-17 18:15 ` [PATCH v5 0/9] smb: client: fix OOB reads and UAFs in SMB2/3 receive paths Paulo Alcantara
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox