Re: [PATCH] smb: client: fix use-before-check of ReparseDataLength in reparse_buf_ptr()

Paulo Alcantara <[email protected]>
Newsgroups org.kernel.vger.linux-cifs,org.kernel.vger.stable
Message-ID <[email protected]>
Frank Sorenson <[email protected]> writes:

> reparse_buf_ptr() reads buf->ReparseDataLength before checking that
> count covers the full fixed header:
>
>     buf = (struct reparse_data_buffer *)((u8 *)io + off);
>     len = sizeof(*buf);                          /* 8 bytes */
>     rdlen = le16_to_cpu(buf->ReparseDataLength); /* offset 4, 2 bytes */
>
>     if (count < len || count < rdlen + len)      /* check comes after */
>
> struct reparse_data_buffer has ReparseDataLength at offset 4.  If a
> server returns OutputCount < 6, the read at offset 4-5 reaches past
> the end of the received data.  The off+count bounds against iov_len
> were already validated, but that does not protect against count being
> smaller than sizeof(*buf).
>
> Split the check: verify count >= sizeof(*buf) before reading
> ReparseDataLength, then verify count covers the data region.
>
> Fixes: a158bb66b137 ("smb: client: optimise reparse point querying")
> Cc: [email protected]
> Signed-off-by: Frank Sorenson <[email protected]>

Acked-by: Paulo Alcantara (Red Hat) <[email protected]>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.