From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mx3-rdu2.redhat.com ([66.187.233.73]:51556 "EHLO mx1.redhat.com" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S1753317AbeGEQAr (ORCPT ); Thu, 5 Jul 2018 12:00:47 -0400 Date: Thu, 5 Jul 2018 18:00:38 +0200 From: Stefano Brivio To: Steve French Cc: =?UTF-8?B?QXVyw6lsaWVu?= Aptel , Steve French , CIFS , Ronnie Sahlberg , jiyin@redhat.com, Pavel Shilovskiy , Shirish Pargaonkar , Stable Subject: Re: [PATCH] cifs: Fix slab-out-of-bounds in send_set_info() on SMB2 ACE setting Message-ID: <20180705180039.51700198@epycfail> In-Reply-To: References: <87d0w17nu3.fsf@suse.com> MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8BIT Sender: stable-owner@vger.kernel.org List-ID: On Thu, 5 Jul 2018 09:55:49 -0500 Steve French wrote: > On Thu, Jul 5, 2018 at 9:35 AM Aurélien Aptel wrote: > > > > Stefano Brivio writes: > > > /* BB eventually switch this to SMB2 specific small buf size */ > > > - *request_buf = cifs_small_buf_get(); > > > + if (smb2_command == SMB2_SET_INFO) > > > + *request_buf = cifs_buf_get(); > > > + else > > > + *request_buf = cifs_small_buf_get(); > > > if (*request_buf == NULL) { > > > /* BB should we add a retry in here if not a writepage? */ > > > return -ENOMEM; > > > @@ -3720,7 +3723,7 @@ send_set_info(const unsigned int xid, struct cifs_tcon *tcon, > > > > > > rc = cifs_send_recv(xid, ses, &rqst, &resp_buftype, flags, > > > &rsp_iov); > > > - cifs_small_buf_release(req); > > > + cifs_buf_release(req); > > > rsp = (struct smb2_set_info_rsp *)rsp_iov.iov_base; > > > > Small and large bufs use different mempools, shouldn't the release func > > match the get func? > > Yes > > Stefano, > Can you respin your patch? I am hoping this patch addresses a bug I > have been seeing Steve, I guess I'm missing something, but I fail to see the mismatch between get and release, now for SMB2_SET_INFO we'll be using cifs_req_poolp in both paths. What should I change? -- Stefano