Re: [PATCH] smb: client: restore the data_offset bound in is_valid_oplock_break()

Paulo Alcantara <[email protected]>
Newsgroups org.kernel.vger.linux-cifs,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
Bryam Vargas via B4 Relay <[email protected]>
writes:

> From: Bryam Vargas <[email protected]>
>
> Commit 83bfbd0bb902 ("cifs: Remove the RFC1002 header from smb_hdr")
> changed the quantity this bound is measured against.  It used to be
> srv->total_read minus the 4-byte RFC1002 preamble that total_read then
> included, so it was the SMB message length.  The same commit stopped
> counting the preamble, and the mechanical substitution to
> srv->total_read - srv->pdu_size left an expression that is identically
> zero: standard_receive3() reads MID_HEADER_SIZE() bytes and then exactly
> pdu_length - MID_HEADER_SIZE() more, adding both to total_read.
>
> len is therefore 0, the subtraction below it wraps, and no __u32
> DataOffset can exceed the result, so the check from commit 097f5863b1a0
> ("cifs: read overflow in is_valid_oplock_break()") no longer rejects
> anything.  Use total_read, which is now the message length on its own.
> ...

Applied.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.