From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7E58B3F58D9; Wed, 23 Sep 2026 14:34:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790174057; cv=none; b=O7lLVClL0wWRhHMvoJvClD0GYX+jF7hXPPFHWjDhrqLjK+yme5aBrHvHJysdMJ7mwXfzmWovQ3F/Kkx3DwZfbdaTb1ha7FQvLpuzQaS7vnZcy0Hti5RPhMxQGCn0fb0KKPvs+NenUdtkNA0G28BhJm7LWjRpwiSnoMbWX3dYESc= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790174057; c=relaxed/simple; bh=Z6r+30m+oYGf2Gq+dOLaOXJISsMPyR+BZjlCSB9SDz0=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=P1SHep7IyXIAKhs+6r3JxvDD0KSnwSEDR9rU34NPNozimG2mdI/+DgSvddIN/FEtRldYQu2SieJjUjNqkdtIvo5KdS2WD5R/Jak7CXGOlfBv8jFO3Mi2qxIltfJcG+C+LVVfVLpv1nuds6W6Ypi6mrOjx5c6ICP+/CmejwLhIp8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=o37exCLT; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="o37exCLT" Received: by smtp.kernel.org (Postfix) with ESMTPSA id D5D871F00893; Wed, 23 Sep 2026 14:34:15 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790174056; bh=8j02vWoxwVT7ux/Yh8My7w5r8/rDSmZlvhKHqAn1DSQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=o37exCLTQibmaZnYzwRGYW+gNNbZYqKVUwf/4VChkBG7ahfCh5giuK2Y5z7X0A5ag Chto7TZWcvrDRYjC8XQ9FYWovzMmWfDkKGMCpAjnJI7I4McWO9ugQF11fHDy13140t KgoOc2O+oZzCw8ZNCxSYRVbBOTTn2A09bDv71CMA= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Frank Sorenson , David Howells , Paulo Alcantara Subject: [PATCH 7.2 421/438] smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs Date: Wed, 23 Sep 2026 16:07:22 +0200 Message-ID: <20260923140655.825304531@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260923140644.756254324@linuxfoundation.org> References: <20260923140644.756254324@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 7.2-stable review patch. If anyone has any objections, please let me know. ------------------ From: Frank Sorenson commit 05762c5bc1cfdcac36747994fde2c04387a457f1 upstream. Fix several related bounds checking and pointer lifecycle issues in receive_encrypted_standard()'s handling of compound encrypted frames: - Clear next_buffer after assigning it to server->bigbuf. A stale next_buffer pointer can lead to a use-after-free on subsequent error paths. - Update pdu_length to the decrypted plaintext size (buf_size). Using the pre-decryption length allows NextCommand to point into stale ciphertext residue. - Reject next_cmd values smaller than MID_HEADER_SIZE(server). - Fix an integer overflow in the upper bound check by verifying pdu_length - next_cmd < MID_HEADER_SIZE(server), ensuring the trailing slice is large enough for a header. Fixes: b24df3e30cbf ("cifs: update receive_encrypted_standard to handle compounded responses") Cc: stable@vger.kernel.org Signed-off-by: Frank Sorenson Reviewed-by: David Howells Signed-off-by: Paulo Alcantara Signed-off-by: Greg Kroah-Hartman --- fs/smb/client/smb2ops.c | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) --- a/fs/smb/client/smb2ops.c +++ b/fs/smb/client/smb2ops.c @@ -5362,6 +5362,7 @@ receive_encrypted_standard(struct TCP_Se length = decrypt_raw_data(server, buf, buf_size, NULL, false); if (length) return length; + pdu_length = buf_size; next_is_large = server->large_buf; one_more: @@ -5374,8 +5375,15 @@ one_more: } if (next_cmd) { - if (WARN_ON_ONCE(next_cmd > pdu_length)) + if (next_cmd < MID_HEADER_SIZE(server) || + next_cmd > pdu_length || + pdu_length - next_cmd < MID_HEADER_SIZE(server)) { + unsigned int max_next = pdu_length > (unsigned int)MID_HEADER_SIZE(server) ? + pdu_length - (unsigned int)MID_HEADER_SIZE(server) : 0; + cifs_server_dbg(VFS, "invalid NextCommand offset %u out of range [%zu, %u]\n", + next_cmd, MID_HEADER_SIZE(server), max_next); return -1; + } if (next_is_large) next_buffer = (char *)cifs_buf_get(); else @@ -5411,6 +5419,7 @@ one_more: server->bigbuf = buf = next_buffer; else server->smallbuf = buf = next_buffer; + next_buffer = NULL; goto one_more; } else if (ret != 0) { /*