Re: [PATCH v2] smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2()
Namjae Jeon <[email protected]>
| Newsgroups | org.kernel.vger.linux-cifs,org.kernel.vger.stable |
|---|---|
| Message-ID | <CAKYAXd8NjLwerXCnR8X5RDuD15Rc+by2z8T1taXuHw5t_-cCZg@mail.gmail.com> |
On Wed, Aug 12, 2026 at 11:42 AM Frank Sorenson <[email protected]> wrote: > > coalesce_t2() computes data pointers directly from server-supplied > DataOffset fields with no validation against buffer bounds: > > data_area_of_tgt = (char *)&pSMBt->hdr.Protocol + > get_unaligned_le16(&pSMBt->t2_rsp.DataOffset); > data_area_of_src = (char *)&pSMBs->hdr.Protocol + > get_unaligned_le16(&pSMBs->t2_rsp.DataOffset); > data_area_of_tgt += total_in_tgt; > ... > memcpy(data_area_of_tgt, data_area_of_src, total_in_src); > > A small DataOffset can push a pointer below the actual byte area, > overwriting header fields; a large one can push it past the buffer > end, causing out-of-bounds heap reads (source) or writes (target). > The BCC overflow guard does not prevent this: BCC reflects how much > data is present, while DataOffset controls where in the buffer it > starts. > > The "validate target area" comment present since the function was > first written in 2005 was a placeholder that was never implemented. > > Add lower- and upper-bound checks for both data pointers before the > memcpy, and before any target header fields are modified. > > Fixes: e4eb295d38b5 ("[PATCH] cifs: Handle multiple response transact2 part 1 of 2") > Cc: [email protected] > Reported-by: Shen Yongchao <[email protected]> > Signed-off-by: Frank Sorenson <[email protected]> Will appy it to #for-next. Thanks!