Re: [PATCH] smb: client: fix ALIGN() overflow in symlink_data() error context loop
Paulo Alcantara <[email protected]>
| Newsgroups | org.kernel.vger.stable,org.kernel.vger.linux-cifs |
|---|---|
| Message-ID | <[email protected]> |
Frank Sorenson <[email protected]> writes: > The check added by commit 7d9a7f1f96cd compared the post-ALIGN length > against the remaining buffer, but ALIGN() itself can overflow: for > ErrorDataLength near UINT32_MAX (e.g. 0xFFFFFFF9), ALIGN(x, 8) wraps > to 0, so the subsequent bounds check passes, and the loop advances by > zero bytes leaving 'p' pointing into stale data. > > Fix by checking the raw ErrorDataLength against the remaining space > before applying ALIGN(), then checking again after. Since raw_len is > bounded by the buffer, raw_len + 7 cannot overflow, so the second check > is an exact post-alignment bounds guard. > > Fixes: 76894f3e2f71 ("cifs: improve symlink handling for smb2+") > Cc: [email protected] > Signed-off-by: Frank Sorenson <[email protected]> Acked-by: Paulo Alcantara (Red Hat) <[email protected]>