Re: [PATCH v3] smb: client: reject a tree connect response whose byte count is too small
Namjae Jeon <[email protected]>
| Newsgroups | org.kernel.vger.linux-cifs,dev.linux.lists.llvm,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <CAKYAXd8+HNjk-BXZVnv0_wwp+E-S5__gt_wKnCCmrkRv7eMPhA@mail.gmail.com> |
On Fri, Aug 21, 2026 at 9:36 PM Bryam Vargas via B4 Relay <[email protected]> wrote: > > From: Bryam Vargas <[email protected]> > > CIFSTCon() bounds its strnlen() over the byte area with the server's > ByteCount minus two, which for ByteCount 0 or 1 goes negative as an int > and converts to a huge size_t. The later subtraction wraps the __u16 > bytes_left, and that is what bounds cifs_strndup_from_utf16(): a bound of > up to 65535 against a ~16 KB cifs_req_poolp object runs off the end of the > slab object, and the bytes reach userspace through tcon->nativeFileSystem > in /proc/fs/cifs/DebugData. > > Reject a byte area too small for what the parser consumes. Two bytes is > the least it can consume, and no conformant response carries fewer. The > new trace point is the 129th smb_eio_trace entry, which __mode(byte) > cannot represent, so the attribute goes with it. > > Fixes: cc20c031bb06 ("cifs: convert CIFSTCon to use new unicode helper functions") > Cc: [email protected] > Signed-off-by: Bryam Vargas <[email protected]> Reviewed-by: Namjae Jeon <[email protected]> Thanks.