Re: [PATCH] smb: client: fix ALIGN() overflow in symlink_data() error context loop

Paulo Alcantara <[email protected]>
Newsgroups org.kernel.vger.stable,org.kernel.vger.linux-cifs
Message-ID <[email protected]>
Frank Sorenson <[email protected]> writes:

> The check added by commit 7d9a7f1f96cd compared the post-ALIGN length
> against the remaining buffer, but ALIGN() itself can overflow: for
> ErrorDataLength near UINT32_MAX (e.g. 0xFFFFFFF9), ALIGN(x, 8) wraps
> to 0, so the subsequent bounds check passes, and the loop advances by
> zero bytes leaving 'p' pointing into stale data.
>
> Fix by checking the raw ErrorDataLength against the remaining space
> before applying ALIGN(), then checking again after.  Since raw_len is
> bounded by the buffer, raw_len + 7 cannot overflow, so the second check
> is an exact post-alignment bounds guard.
>
> Fixes: 76894f3e2f71 ("cifs: improve symlink handling for smb2+")
> Cc: [email protected]
> Signed-off-by: Frank Sorenson <[email protected]>

Acked-by: Paulo Alcantara (Red Hat) <[email protected]>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.