From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 364A93515DC; Wed, 30 Sep 2026 19:28:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790796509; cv=none; b=i9ysfS6ygx/H7f7H5YZvNi3Zo+hyL5f8LShXYkPGHnR7QZpsq4uoSdLF1P6Rp2apWngjL0XcVrZKLXSFOBDCCwpVoZbxWyER4E9dPp6SlKt1Dqyq3XwlDt92U/N7C7ibXaR9pDtdhPIGVd55TUAlU2522HrOSiYgESHoCeWiiFQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790796509; c=relaxed/simple; bh=P8rzaTDqHRAfNt6QljqgcYHOQ6uxbkePts9+HUWUXVI=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=mDAmwMaRJPdwq/7IdVT/aa7B3wsqc+sh1N8fUIBU+qaZ5E1SL7fffykLQxRWGCVGpDf11yc2Cyse2vwf3BxfKliugDURtm0J9aaPGtCadxNPkCi+bkTWLUa6MiiJ2nEGOr0l5/IdKs5NkLfHBUgD8KJDXbZ7IvsUbAJiUGMi9i0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=x6VietLp; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="x6VietLp" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 437101F00898; Wed, 30 Sep 2026 19:28:27 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790796507; bh=CuROB8Nelzi8zowu5kognyZVKWGj91erX6Vhtvf8lw4=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=x6VietLpN8oCVM0QcoDuyW/8pKS8S83bDMGxYPFEBcEKClJVKfxSnqIERs7XsXE4S kfqTOtDL2iTHXr5miEx80wctDqgTN9SP2iNOtIb552EwYLNtGpWzKdBmMENs4uC0tt SdW80KFxn+sgzd2gRzs/Saq+aStCDlh0hTAzmxRg= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Frank Sorenson , David Howells , Paulo Alcantara Subject: [PATCH 6.6 0937/1193] smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs Date: Wed, 30 Sep 2026 17:27:01 +0200 Message-ID: <20260930152455.059205844@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152434.301151190@linuxfoundation.org> References: <20260930152434.301151190@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.6-stable review patch. If anyone has any objections, please let me know. ------------------ From: Frank Sorenson commit 05762c5bc1cfdcac36747994fde2c04387a457f1 upstream. Fix several related bounds checking and pointer lifecycle issues in receive_encrypted_standard()'s handling of compound encrypted frames: - Clear next_buffer after assigning it to server->bigbuf. A stale next_buffer pointer can lead to a use-after-free on subsequent error paths. - Update pdu_length to the decrypted plaintext size (buf_size). Using the pre-decryption length allows NextCommand to point into stale ciphertext residue. - Reject next_cmd values smaller than MID_HEADER_SIZE(server). - Fix an integer overflow in the upper bound check by verifying pdu_length - next_cmd < MID_HEADER_SIZE(server), ensuring the trailing slice is large enough for a header. Fixes: b24df3e30cbf ("cifs: update receive_encrypted_standard to handle compounded responses") Cc: stable@vger.kernel.org Signed-off-by: Frank Sorenson Reviewed-by: David Howells Signed-off-by: Paulo Alcantara Signed-off-by: Greg Kroah-Hartman --- fs/smb/client/smb2ops.c | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) --- a/fs/smb/client/smb2ops.c +++ b/fs/smb/client/smb2ops.c @@ -4963,6 +4963,7 @@ receive_encrypted_standard(struct TCP_Se length = decrypt_raw_data(server, buf, buf_size, NULL, false); if (length) return length; + pdu_length = buf_size; next_is_large = server->large_buf; one_more: @@ -4975,8 +4976,15 @@ one_more: } if (next_cmd) { - if (WARN_ON_ONCE(next_cmd > pdu_length)) + if (next_cmd < MID_HEADER_SIZE(server) || + next_cmd > pdu_length || + pdu_length - next_cmd < MID_HEADER_SIZE(server)) { + unsigned int max_next = pdu_length > (unsigned int)MID_HEADER_SIZE(server) ? + pdu_length - (unsigned int)MID_HEADER_SIZE(server) : 0; + cifs_server_dbg(VFS, "invalid NextCommand offset %u out of range [%zu, %u]\n", + next_cmd, MID_HEADER_SIZE(server), max_next); return -1; + } if (next_is_large) next_buffer = (char *)cifs_buf_get(); else @@ -5012,6 +5020,7 @@ one_more: server->bigbuf = buf = next_buffer; else server->smallbuf = buf = next_buffer; + next_buffer = NULL; goto one_more; } else if (ret != 0) { /*