Re: [PATCH] smb: client: restore the data_offset bound in is_valid_oplock_break()
Paulo Alcantara <[email protected]>
| Newsgroups | org.kernel.vger.linux-cifs,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <[email protected]> |
Bryam Vargas via B4 Relay <[email protected]> writes: > From: Bryam Vargas <[email protected]> > > Commit 83bfbd0bb902 ("cifs: Remove the RFC1002 header from smb_hdr") > changed the quantity this bound is measured against. It used to be > srv->total_read minus the 4-byte RFC1002 preamble that total_read then > included, so it was the SMB message length. The same commit stopped > counting the preamble, and the mechanical substitution to > srv->total_read - srv->pdu_size left an expression that is identically > zero: standard_receive3() reads MID_HEADER_SIZE() bytes and then exactly > pdu_length - MID_HEADER_SIZE() more, adding both to total_read. > > len is therefore 0, the subtraction below it wraps, and no __u32 > DataOffset can exceed the result, so the check from commit 097f5863b1a0 > ("cifs: read overflow in is_valid_oplock_break()") no longer rejects > anything. Use total_read, which is now the message length on its own. > ... Applied.