Re: [PATCH v3] smb: client: reject a tree connect response whose byte count is too small

Namjae Jeon <[email protected]>
Newsgroups org.kernel.vger.linux-cifs,dev.linux.lists.llvm,org.kernel.vger.linux-kernel
Message-ID <CAKYAXd8+HNjk-BXZVnv0_wwp+E-S5__gt_wKnCCmrkRv7eMPhA@mail.gmail.com>
On Fri, Aug 21, 2026 at 9:36 PM Bryam Vargas via B4 Relay
<[email protected]> wrote:
>
> From: Bryam Vargas <[email protected]>
>
> CIFSTCon() bounds its strnlen() over the byte area with the server's
> ByteCount minus two, which for ByteCount 0 or 1 goes negative as an int
> and converts to a huge size_t.  The later subtraction wraps the __u16
> bytes_left, and that is what bounds cifs_strndup_from_utf16(): a bound of
> up to 65535 against a ~16 KB cifs_req_poolp object runs off the end of the
> slab object, and the bytes reach userspace through tcon->nativeFileSystem
> in /proc/fs/cifs/DebugData.
>
> Reject a byte area too small for what the parser consumes.  Two bytes is
> the least it can consume, and no conformant response carries fewer.  The
> new trace point is the 129th smb_eio_trace entry, which __mode(byte)
> cannot represent, so the attribute goes with it.
>
> Fixes: cc20c031bb06 ("cifs: convert CIFSTCon to use new unicode helper functions")
> Cc: [email protected]
> Signed-off-by: Bryam Vargas <[email protected]>
Reviewed-by: Namjae Jeon <[email protected]>
Thanks.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.