Re: [PATCH 1/2] smb: client: fix off-by-8 bounds check in check_wsl_eas()

Greg Kroah-Hartman <[email protected]> Wed, 8 Apr 2026 07:39:08 +0200
Newsgroups gmane.linux.kernel,gmane.linux.kernel.cifs,gmane.network.samba.internals,gmane.linux.kernel.stable
Message-ID <2026040822-shortly-chump-8518@gregkh>
On Wed, Apr 08, 2026 at 10:51:12AM +0800, ChenXiaoSong wrote:
> Sashiko reported another out-of-bounds issue:
> https://sashiko.dev/#/patchset/2026040635-banking-unsoiled-3250@gregkh
> 
> Should we add the following checks in check_wsl_eas()?
> 
> ```
> --- a/fs/smb/client/smb2inode.c
> +++ b/fs/smb/client/smb2inode.c
> @@ -121,6 +121,9 @@ static int check_wsl_eas(struct kvec *rsp_iov)
>         ea = (void *)((u8 *)rsp_iov->iov_base +
>                       le16_to_cpu(rsp->OutputBufferOffset));
>         end = (u8 *)rsp_iov->iov_base + rsp_iov->iov_len;
> +       if (ea + outlen > end)
> +               return -EINVAL;

Then you would miss any "first" structures here, as I think the for loop
catches this later on with the line:


> +
>         for (;;) {
>                 if ((u8 *)ea > end - sizeof(*ea))
>                         return -EINVAL;

That one, right?

Or am I misreading this?

Pointer math is "fun" :(

thanks,

greg k-h