From nobody Sat Jul 25 23:42:05 2026 Received: from mail-pl1-f177.google.com (mail-pl1-f177.google.com [209.85.214.177]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 427991E5B88 for ; Sat, 11 Jul 2026 13:33:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.177 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783776829; cv=none; b=OeZkvTqfbUGcUICPfejHnjZXsHw4orUJgnBAwWQwvjDZ/SxGdNkjkGpCfpICM4gg4HHO5UQ+76iVHoAT1b+gtdv/yvMd1v/4Qar88eOdjwfwD0M44QdRbArtKp1YQYuP3sDYiA8JWXAZTndlWHZD5PsBXW/B0WYobrQnn86cdjo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783776829; c=relaxed/simple; bh=ZnX556/SgTs5R4D8I5uTvWRq0Qb0EKx6Zma/xbvdxNU=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=IPidVgfK16Amb5MHBO/ERm2NHRr4HTk2F33gphkMIPzy/W5SVFLnaAogjeAk+sQ8FUHV2S2C1sV41wweoPaKa40yRS2fSMcYW1LI8vm6ItRdpnl7/RsUIwaQRiw8jyQWJs6xpvybijNr0/3tZKPZQCtTSVuhVlYEcCmW8waYkd8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=dclwXbuf; arc=none smtp.client-ip=209.85.214.177 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="dclwXbuf" Received: by mail-pl1-f177.google.com with SMTP id d9443c01a7336-2ceaf8a1265so2368725ad.2 for ; Sat, 11 Jul 2026 06:33:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1783776828; x=1784381628; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=6KR19s9LTdwg8fzyf+W0+BdWpTP82F88oIsv5vsjL+8=; b=dclwXbufeOSPF4/r2U3MIOJbsVJlatFu0NI2xfyMpRoyUk1GPZoLcwcXgxkaLoJVTr OY2nnzJMk6xYysLf31jGPDXzFozFmJyqn+/TNfoGd4Yo151JxdYF9Bm28Ta+XYUfuFn6 KepQRmiBwxd1EZrZVmigE9IkNEb10Vptbx4HyxyITdFQQ0W9epUVN3g5AdV9liOCvDYb 85INCZyOAs6ZK2TfMiJMSq3R1mfq5q416HlGtRTcMT5TYnXFFcXsq6yhv/bsDVv6QLog HVy5V6waSsBxjpLcr9hgdYoFqBbOGitYzYI+aiIrqUSaSWV8x2bXxApuKVjop5k+HQq9 tMFw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783776828; x=1784381628; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=6KR19s9LTdwg8fzyf+W0+BdWpTP82F88oIsv5vsjL+8=; b=KD0eCQTJCz7te4KdiTk9k1NEZL4fDGCzTaazn1cjHCK3bdGGAAlLSZE7iryKNLuwjc 1MnalhGijpAgX5fndIfc7nQiqUrawfsvKGcmnAEzz/P7LOOxXP+LXUz5MIFtfmkO+Nhb KZhUyl0dxy3PtsDO13xWvgPP8J8a7R+6hVIaid3Mmkojsx2pMq5WzjcG5ohB7geWkjxp 7vUsrSRBvYvF4+T3H03vxwHVENO3beFl6cP59VapcbPisVeoxuJd7tMe2JvPycWJdMMK LPM7TpY3biywMIQ2hosXyI6jkJudvBEd+mLOn+dLiqyVrTq/1HirgWjTj4f2kk5Ai+fZ Fgfg== X-Forwarded-Encrypted: i=1; AHgh+RrCr4DPCPzjA/a0eWt4MJQ8zUT7qxXRj7ztd1OxLXDEcLWYYnNKYlpJuIdZagxpKL3TprhG1dOqgxuIOJU=@vger.kernel.org X-Gm-Message-State: AOJu0YxUreRBZFld2X8phPHnfiSEWiDNrvG+peZZTKWA8Sx8LEALkbkW OSJVz+eRZlpw4zCCZTRzDg7zWxkKjX4TNWd+8DQ9Sa+tipPt43l1v5aX X-Gm-Gg: AfdE7ck47xaTWJg7x+KHUdqR4YVoWuJKSxn0GR/czouMUodwRQQEZQshoR6XlPI3NMh jHK7ugzuAOJH+O1DLRwcg8r5HBSP8U2Zv7PxmBzAhPL5liMNHKA15e+TWP+EHEKNb3VpwMHfI4T 5dAweo8UBQ+o9VZYITXvxrnKKHe7gF5cyce7vm7dg8j9d05IevwOG5qttZ8lfd/gVxrtI6dExit w1a0xCFBEJumcijOQQWqjOXQ9HmMD2B4BLJ/1MljTfzNuSEt4yUTYQaZyfLF/Yk6JaJ9/Au8Axa izL95R6RD8PbfcvnN1nhUCMQoYMvxvj77qPEeIQ++LWjg7UgyfUJtSCs355h0+LjPZm4L29Qa89 27ns2c1kWFO+k4g0xg/T5YUPBBkapZJRHEmIYVZgrPynM71zIWyOEdNZ4eDLgEjSW+fy8EouhkC l0CZOtPd+UP3Vy3NH/xy+zCAecMeJ/PxfV1AfGXMWWVRGNydPYKu5CzhFZZ4q5+jesuKfQboPv7 dIRRZK4loIlGVgN X-Received: by 2002:a17:903:292:b0:2c9:97a8:8c17 with SMTP id d9443c01a7336-2ce9f28802fmr29334865ad.42.1783776827559; Sat, 11 Jul 2026 06:33:47 -0700 (PDT) Received: from localhost.localdomain (116-91-131-11.east.dxpn.ucom.ne.jp. [116.91.131.11]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2ccc9bdb76asm76179555ad.12.2026.07.11.06.33.43 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Sat, 11 Jul 2026 06:33:46 -0700 (PDT) From: Shoichiro Miyamoto To: Steve French , linux-cifs@vger.kernel.org Cc: Paulo Alcantara , Ronnie Sahlberg , Shyam Prasad N , Tom Talpey , Bharath SM , Steve French , samba-technical@lists.samba.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org, Shoichiro Miyamoto Subject: [PATCH] smb: client: reject overlapping data areas in SMB2 responses Date: Sat, 11 Jul 2026 22:33:26 +0900 Message-ID: <20260711133326.94832-1-shoichiro.miyamoto@gmail.com> X-Mailer: git-send-email 2.50.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Commit 53b7c271f06b ("smb: client: restrict implied bcc[0] exemption to responses without data area") restricted the implied bcc[0] length exception to responses without a data area. However, the overlap handling in __smb2_calc_size() clears data_length, which can make an invalid response appear to have no data area and so qualify for the exception. Track data area overlap separately and reject such responses before applying the length compatibility exceptions. Fixes: 53b7c271f06b ("smb: client: restrict implied bcc[0] exemption to res= ponses without data area") Cc: stable@vger.kernel.org Signed-off-by: Shoichiro Miyamoto --- fs/smb/client/smb2misc.c | 34 +++++++++++++++++++++++++--------- 1 file changed, 25 insertions(+), 9 deletions(-) diff --git a/fs/smb/client/smb2misc.c b/fs/smb/client/smb2misc.c index 6270b33147d2..9068175e57cd 100644 --- a/fs/smb/client/smb2misc.c +++ b/fs/smb/client/smb2misc.c @@ -19,7 +19,8 @@ #include "nterr.h" #include "cached_dir.h" =20 -static unsigned int __smb2_calc_size(void *buf, bool *have_data); +static unsigned int __smb2_calc_size(void *buf, bool *have_data, + bool *data_area_overlap); =20 static int check_smb2_hdr(struct smb2_hdr *shdr, __u64 mid) @@ -148,6 +149,7 @@ smb2_check_message(char *buf, unsigned int pdu_len, uns= igned int len, __u32 calc_len; /* calculated length */ __u64 mid; bool have_data; + bool data_area_overlap; =20 /* If server is a channel, select the primary channel */ pserver =3D SERVER_IS_CHAN(server) ? server->primary_server : server; @@ -232,7 +234,12 @@ smb2_check_message(char *buf, unsigned int pdu_len, un= signed int len, } =20 have_data =3D false; - calc_len =3D __smb2_calc_size(buf, &have_data); + data_area_overlap =3D false; + calc_len =3D __smb2_calc_size(buf, &have_data, &data_area_overlap); + + /* Reject responses whose data area overlaps the fixed area. */ + if (data_area_overlap) + return 1; =20 /* For SMB2_IOCTL, OutputOffset and OutputLength are optional, so might * be 0, and not a real miscalculation */ @@ -416,14 +423,15 @@ smb2_get_data_area_len(int *off, int *len, struct smb= 2_hdr *shdr) } =20 /* - * Calculate the size of the SMB message based on the fixed header - * portion, the number of word parameters and the data portion of the mess= age. - * If have_data is non-NULL, it is set to true when a non-empty data area = was - * found (data_length > 0), allowing callers to distinguish the implied bc= c[0] - * case (no data area) from an overreported data length. + * Calculate the size of the SMB message based on the fixed header, fixed + * parameter area, and variable data area. + * + * If have_data is not NULL, it is set when a non-empty data area is found. + * If data_area_overlap is not NULL, it is set when the data area overlaps + * the fixed area. */ static unsigned int -__smb2_calc_size(void *buf, bool *have_data) +__smb2_calc_size(void *buf, bool *have_data, bool *data_area_overlap) { struct smb2_pdu *pdu =3D buf; struct smb2_hdr *shdr =3D &pdu->hdr; @@ -432,6 +440,11 @@ __smb2_calc_size(void *buf, bool *have_data) /* Structure Size has already been checked to make sure it is 64 */ int len =3D le16_to_cpu(shdr->StructureSize); =20 + if (have_data) + *have_data =3D false; + if (data_area_overlap) + *data_area_overlap =3D false; + /* * StructureSize2, ie length of fixed parameter area has already * been checked to make sure it is the correct length. @@ -454,7 +467,10 @@ __smb2_calc_size(void *buf, bool *have_data) if (offset + 1 < len) { cifs_dbg(VFS, "data area offset %d overlaps SMB2 header %d\n", offset + 1, len); + if (data_area_overlap) + *data_area_overlap =3D true; data_length =3D 0; + goto calc_size_exit; } else { len =3D offset + data_length; } @@ -469,7 +485,7 @@ __smb2_calc_size(void *buf, bool *have_data) unsigned int smb2_calc_size(void *buf) { - return __smb2_calc_size(buf, NULL); + return __smb2_calc_size(buf, NULL, NULL); } =20 /* Note: caller must free return buffer */ --=20 2.50.1 (Apple Git-155)