Re: [PATCH] smb: client: require a full NFS mode SID before reading mode bits
Steve French <[email protected]> Mon, 20 Apr 2026 15:55:46 -0500
| Newsgroups | gmane.linux.kernel.stable,gmane.linux.kernel.cifs,gmane.network.samba.internals,gmane.linux.kernel |
|---|---|
| Message-ID | <CAH2r5mtNhVtN65gYcbPqxOXMD_Fm3FcHFcURLmF8yma2zKk1aw@mail.gmail.com> |
This patch wouldn't apply due to a conflict with "smb: client: validate the whole DACL before rewriting it in cifsacl" Had to change "end_of_acl" to "end_of_dacl" See attached. On Mon, Apr 20, 2026 at 10:14 AM Michael Bommarito <[email protected]> wrote: > > parse_dacl() treats an ACE SID matching sid_unix_NFS_mode as an NFS > mode SID and reads sid.sub_auth[2] to recover the mode bits. > > That assumes the ACE carries three subauthorities, but compare_sids() > only compares min(a, b) subauthorities. A malicious server can return > an ACE with num_subauth = 2 and sub_auth[] = {88, 3}, which still > matches sid_unix_NFS_mode and then drives the sub_auth[2] read four > bytes past the end of the ACE. > > Require num_subauth >= 3 before treating the ACE as an NFS mode SID. > This keeps the fix local to the special-SID mode path without changing > compare_sids() semantics for the rest of cifsacl. > > Fixes: e2f8fbfb8d09 ("cifs: get mode bits from special sid on stat") > Cc: [email protected] > Assisted-by: Claude:claude-opus-4-6 > Signed-off-by: Michael Bommarito <[email protected]> > --- > fs/smb/client/cifsacl.c | 1 + > 1 file changed, 1 insertion(+) > > diff --git a/fs/smb/client/cifsacl.c b/fs/smb/client/cifsacl.c > index c920039d733c..a62c8a733779 100644 > --- a/fs/smb/client/cifsacl.c > +++ b/fs/smb/client/cifsacl.c > @@ -831,6 +831,7 @@ static void parse_dacl(struct smb_acl *pdacl, char *end_of_acl, > dump_ace(ppace[i], end_of_acl); > #endif > if (mode_from_special_sid && > + ppace[i]->sid.num_subauth >= 3 && > (compare_sids(&(ppace[i]->sid), > &sid_unix_NFS_mode) == 0)) { > /* > -- > 2.53.0 > > -- Thanks, Steve
0001-smb-client-require-a-full-NFS-mode-SID-before-readin.patch
(text/x-patch, 1.6 KB)
From 5a3980f30275601d69e066290d2884bb5af2dd28 Mon Sep 17 00:00:00 2001 From: Michael Bommarito <[email protected]> Date: Mon, 20 Apr 2026 09:50:58 -0400 Subject: [PATCH] smb: client: require a full NFS mode SID before reading mode bits parse_dacl() treats an ACE SID matching sid_unix_NFS_mode as an NFS mode SID and reads sid.sub_auth[2] to recover the mode bits. That assumes the ACE carries three subauthorities, but compare_sids() only compares min(a, b) subauthorities. A malicious server can return an ACE with num_subauth = 2 and sub_auth[] = {88, 3}, which still matches sid_unix_NFS_mode and then drives the sub_auth[2] read four bytes past the end of the ACE. Require num_subauth >= 3 before treating the ACE as an NFS mode SID. This keeps the fix local to the special-SID mode path without changing compare_sids() semantics for the rest of cifsacl. Fixes: e2f8fbfb8d09 ("cifs: get mode bits from special sid on stat") Cc: [email protected] Assisted-by: Claude:claude-opus-4-6 Signed-off-by: Michael Bommarito <[email protected]> Signed-off-by: Steve French <[email protected]> --- fs/smb/client/cifsacl.c | 1 + 1 file changed, 1 insertion(+) diff --git a/fs/smb/client/cifsacl.c b/fs/smb/client/cifsacl.c index c920039d733c..a62c8a733779 100644 --- a/fs/smb/client/cifsacl.c +++ b/fs/smb/client/cifsacl.c @@ -831,6 +831,7 @@ static void parse_dacl(struct smb_acl *pdacl, char *end_of_acl, dump_ace(ppace[i], end_of_dacl); #endif if (mode_from_special_sid && + ppace[i]->sid.num_subauth >= 3 && (compare_sids(&(ppace[i]->sid), &sid_unix_NFS_mode) == 0)) { /* -- 2.51.0