Re: [PATCH v3] smb: client: reject a tree connect response whose byte count is too small

Paulo Alcantara <[email protected]>
Newsgroups dev.linux.lists.llvm,org.kernel.vger.linux-cifs,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
Bryam Vargas via B4 Relay <[email protected]>
writes:

> From: Bryam Vargas <[email protected]>
>
> CIFSTCon() bounds its strnlen() over the byte area with the server's
> ByteCount minus two, which for ByteCount 0 or 1 goes negative as an int
> and converts to a huge size_t.  The later subtraction wraps the __u16
> bytes_left, and that is what bounds cifs_strndup_from_utf16(): a bound of
> up to 65535 against a ~16 KB cifs_req_poolp object runs off the end of the
> slab object, and the bytes reach userspace through tcon->nativeFileSystem
> in /proc/fs/cifs/DebugData.
>
> Reject a byte area too small for what the parser consumes.  Two bytes is
> the least it can consume, and no conformant response carries fewer.  The
> new trace point is the 129th smb_eio_trace entry, which __mode(byte)
> cannot represent, so the attribute goes with it.
> ...

Applied.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.