From nobody Sat Sep 26 10:03:03 2026 Received: from mail-wm1-f52.google.com (mail-wm1-f52.google.com [209.85.128.52]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 14D1F468C37 for ; Wed, 2 Sep 2026 10:42:29 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.52 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788345753; cv=none; b=E6SNJLvbDXCvRzNntEnFxKjdAfdg9of/lvViB2o0L2MzxCq8Nk5N8okXWVhWgnnPq3rZPxT5HwafUZ1ojcSINNW+LkuEqCnw+3AESF9xk7WWEtWmUuaZKxGBunUDhWqSf52EZO/fvYkloE5Qp10IJj1Ug+C48iJOWwgt0+zPkWg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788345753; c=relaxed/simple; bh=hQh6a2ifXWFj4QrRqHhl9zv3nNrLH7SulfxH91w9/cY=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=L75sz0z2Aeyo436mcB0EOCyTTVIxhOfGR4lI1g3AQUkUmgac5qhAxBaW9dWtrAO3LL2jK8hY57c61ZRH8X6Os/67U787dwgPSOPIOyu8nd90/bp+VPVuupy+EjlEyE1SG4R0f9nop3UInq1K6SQh7wqpRnHIGDckvx9ekaC/Xi0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=bynar.io; spf=pass smtp.mailfrom=bynar.io; dkim=pass (2048-bit key) header.d=bynar.io header.i=@bynar.io header.b=KCjtG5Wx; arc=none smtp.client-ip=209.85.128.52 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=bynar.io Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=bynar.io Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=bynar.io header.i=@bynar.io header.b="KCjtG5Wx" Received: by mail-wm1-f52.google.com with SMTP id 5b1f17b1804b1-49b8687630fso6766455e9.3 for ; Wed, 02 Sep 2026 03:42:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=bynar.io; s=google; t=1788345747; x=1788950547; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=iDiKnKsyrZcQ8QtZ7xdNlsZaf5L7qYJwEj5GZjqkmII=; b=KCjtG5Wxv3PGPS2RbuJHNuqTI1AV5ZZ1kaSa0hPf4fvUCW4dXMPfGSZcnjpkH7x90U f4HHg4Vb6riuIIZmUoLD8XnQACEsz71CULnlRrMV3N5DVKtB5a+5bujLiliioij0C6zi dmrmaFHtzQtOUa1ojdqNbmdCozZYbA5jtBuBWlGkJGGC6MtqFhT94O/jk39d0Gfg1KQi thX6KNelfxbzTdCYcngT3het98KAZhS0L4c0iNP6ADVxg4R0sdcPb0slD+SqpAFAsdth rizcXip0gXJw0U9gbAARP1QZFZWjPqqZ2psFtFDB87gPXk/+yOMKNcD09VqvpyRaHEj4 BSFw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788345747; x=1788950547; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=iDiKnKsyrZcQ8QtZ7xdNlsZaf5L7qYJwEj5GZjqkmII=; b=dzsGRTSC1agj7v291tV8/oekNUDl+317AwwEmQ4E/jcIaLfh3NaSIzRCev/vZRzvqT SU6HcMJkXL7EKs+COQeZ7TY+tG2/B2FjPVfqnQwCQvYD0OK+s/oPmtuhkgrTsiSk900N 8YWwBp246Pn+X/V/1JahGOn0KLbf8wGSJMIPTDRuagpjQBcZsFIWIH93tkThkG4C+SXd C/Y2KGsvfEsVjpiHN9rba1eRK2hm7oJqhWMlC1kTMmWI0oLvNbGGdO9mn2ISW3nfm2Rs y76mlW7fhzkTyBjtvqpKDHlumYnsk06vhbr0bLn1Sv1sxSoSon8yPnNkb+8fPPPWQCf9 Buyw== X-Forwarded-Encrypted: i=1; AHgh+RpMzgmFNQf/bjCsypq4GXcG+2uVSgkLRfCzjUPpYFqAVP64Flb232TjnzUQ8YzCJyPedcgo/CaPbDDs0JA=@vger.kernel.org X-Gm-Message-State: AFuF++ljTfpVIZk7thCH6hkTfodGdeM0dnYoCypl7WkLSHtbV/fMz9TJ UhiBf5HX5ormc6uqWz+cnnXJrYdPNJY1bxBG0/a4H9f1NG32NDrVD2e5cfvTSeRWoVeY X-Gm-Gg: AR+sD11DALbf2Nu7anZ2jtf6Us3x4Zn2eVMCGgK4lrJqtFy07e6evuns5JQ+szKtHko +GpQK0qSx4AfwFmlIma8ujVTfYl8b9iuNfnTEGhnhRiMvUEHI114VL0C1T/dcHyg8kgkWH5vHbi dn4OZaYFgBs0FecLixkYcLcIWuBCKuPbD6ebd/04azN32cA1nibbtAxAAom25VvEPOAyxdcOXx3 vHFRqzIcLgXXDP9suhrUmOEYVTdj62i5QxosPWbL7XjlpuWfq57sB6WR3hjlEa+APh2oY5jp4Y0 jGgd5gMqvSFAiHDABvjZ5wUZ6BGXjHRdgFLsMBLSROhgsoTaqxtOPHws0wp25Zm+Fvutl9EYHJq W9ZG8Cz8GDzAI3P2rTFUBpphcXdxwrame5LLl078NB+MwKi2lGCwbcZekaPItQy5brJR4+NIB8J U6JumKLoWmOXMLm6I0pubKl/WDhKPTXSLevTVIc2tE9vcjzLjamNnjZJ1uETKm5Yqzp+LOFuZ7q xFi6zk8u2lHLdkR+Q== X-Received: by 2002:a05:600c:1d89:b0:49c:ed8f:d094 with SMTP id 5b1f17b1804b1-49ced8fd250mr2291155e9.10.1788345746644; Wed, 02 Sep 2026 03:42:26 -0700 (PDT) Received: from debian12.ucl.ac.uk (eduroam-int-pat-8-79.ucl.ac.uk. [144.82.8.79]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-484492ce5e5sm5197521f8f.36.2026.09.02.03.42.25 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 02 Sep 2026 03:42:26 -0700 (PDT) From: Diego Oliva To: Paulo Alcantara , Namjae Jeon Cc: Ronnie Sahlberg , Shyam Prasad N , Tom Talpey , Bharath SM , linux-cifs@vger.kernel.org, samba-technical@lists.samba.org, linux-kernel@vger.kernel.org Subject: [PATCH v3 1/2] smb: client: reject short READ responses in CIFSSMBRead() Date: Wed, 2 Sep 2026 11:42:06 +0100 Message-Id: <20260902104207.1820332-2-diego@bynar.io> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20260902104207.1820332-1-diego@bynar.io> References: <20260902104207.1820332-1-diego@bynar.io> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" CIFSSMBRead() reads DataLengthHigh, DataLength and DataOffset out of the READ_RSP returned by the server without first checking that a whole READ_RSP was actually received. The length of the response is recorded in rsp_iov.iov_len, but nothing constrains it to be at least read_rsp_size before those fields are dereferenced. A malicious or compromised SMB1 server can return a response shorter than the READ_RSP header, so that parsing the header itself reads past the end of the receive buffer. SMB1 is not negotiated by default; reaching this code requires an explicit vers=3D1.0 mount. Reject the response unless it is at least read_rsp_size bytes long. smb_EIO2() was introduced in v6.19, so this does not apply to older stable trees without returning plain -EIO instead. Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") Suggested-by: Paulo Alcantara Cc: # 6.19.x Assisted-by: Bynario AI Signed-off-by: Diego Oliva --- fs/smb/client/cifssmb.c | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/fs/smb/client/cifssmb.c b/fs/smb/client/cifssmb.c index f5aad5f61dce..aa6b904ad866 100644 --- a/fs/smb/client/cifssmb.c +++ b/fs/smb/client/cifssmb.c @@ -1719,6 +1719,14 @@ CIFSSMBRead(const unsigned int xid, struct cifs_io_p= arms *io_parms, pSMBr =3D (READ_RSP *)rsp_iov.iov_base; if (rc) { cifs_dbg(VFS, "Send error in read =3D %d\n", rc); + } else if (rsp_iov.iov_len < tcon->ses->server->vals->read_rsp_size) { + /* check that the received response can hold a whole READ_RSP */ + cifs_dbg(FYI, "%s: server returned short header. got=3D%zu expected=3D%z= u\n", + __func__, rsp_iov.iov_len, + tcon->ses->server->vals->read_rsp_size); + rc =3D smb_EIO2(smb_eio_trace_read_rsp_short, + rsp_iov.iov_len, tcon->ses->server->vals->read_rsp_size); + *nbytes =3D 0; } else { int data_length =3D le16_to_cpu(pSMBr->DataLengthHigh); data_length =3D data_length << 16; --=20 2.39.5 From nobody Sat Sep 26 10:03:03 2026 Received: from mail-wm1-f41.google.com (mail-wm1-f41.google.com [209.85.128.41]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E422044AB6C for ; Wed, 2 Sep 2026 10:42:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.41 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788345754; cv=none; b=mE1NmDG6jp29to9p7HXPVnn9hL9xM+uZeSHA1DPEwxCGpWJUKEI+zOBCDZerFCCE/pCizGMHMuZzh4XOOjrE0xe9pjNe80sl3nisqdSCYCssv325TuEY7j30i+xG7UTAF/TP9OU4pmR5C9rA4vMIEi1Sn7M8aegBN0Z5lH9dwwA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788345754; c=relaxed/simple; bh=xyYMKLzzCsfncAvDaJj0J+b5UPf66aPFS2Ga9ljseK8=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=RAkH6j0m1tefB+snwfWcznUtnenW1ptsIk/vLc+y95tAlk8jJsZ/DBNRvBRT7dB8eGeZslK1sxFKqfB1C4CjCl3VqT/N3pEVAVYbf8pYSY59oOCP6duTRv1/dJr0qSTK8A+qOqVk9Bj5e1Lwb68689Q70SO8q5FLQafL8Za0tpY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=bynar.io; spf=pass smtp.mailfrom=bynar.io; dkim=pass (2048-bit key) header.d=bynar.io header.i=@bynar.io header.b=Yhz0cfAh; arc=none smtp.client-ip=209.85.128.41 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=bynar.io Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=bynar.io Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=bynar.io header.i=@bynar.io header.b="Yhz0cfAh" Received: by mail-wm1-f41.google.com with SMTP id 5b1f17b1804b1-49a97714f5dso6429835e9.0 for ; Wed, 02 Sep 2026 03:42:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=bynar.io; s=google; t=1788345747; x=1788950547; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=FzrA12XVRpjhCE+SpE7Wp9kAWsl7VDT912zdHqjkACw=; b=Yhz0cfAho8UY67b4afxOXTaB8VnlJUJQoQazyl/tqD7mZVVfctVBfa+EoQssIzKvwc VwGgNTmXnzLIZf9T1+ChpV0GpIPIpustDAKnFH/VIJdv5b7h+BW0WA1VX7zz8i/rSEZu Ug6Z885M3pP/gz15SUtiwiBx7YOPbCbNICTZoKFCsdzuG4zCU2rk2guKyD1i+zShWNGo WeGYtey3SsKxDGyAN8fOYeVFMHJXpx9E1LGCehWX/CW5KNtp6+tgV98MyibmHRxkJ1sH 6gNomp42LfqTw8UWKwzWHIXd8dIDfSQ5KEn3H8vSSFlzXUmYmTPczCM9PyhPf6Azkxab v6Vg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788345747; x=1788950547; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=FzrA12XVRpjhCE+SpE7Wp9kAWsl7VDT912zdHqjkACw=; b=LaL6U+VM9bpE+oMfW2Hjh/Tuy/zw1q21lHcVS/6ro/5u+mWwYLMrlcf420bhEkD85L B6brAOJDa+fT0Rj6a6AcJf4Mvr2kNGniJ6BnSC7WNGXZgHCb0hWmL3+1TSC63+G43H0S U6EsJCyPPkWhsFV+Meuld6Yr3lietotJvYodYOiMheDuduw/gVwrXQukANx5Bn+9YOhu qPRBleUZnNK3ZfWZm410WxMkFnLyZh3HnwJViFDfaihEZOw0CRJkmVBX98K0pLbnG7Rl ZsBctQKyCIgWAiwBW+3s/UYCSobUNfkg6oCMQkfletZhfKfP0tvwGEbLh4KLRRCdXAiY rI8A== X-Forwarded-Encrypted: i=1; AHgh+RqJ0YDmjboT/XCOVCvBNNLvV6D0IPAEeEVMQvCtnPZuRnrcD3QPr9Ov8LbmA/B96e9tFRR1jzcY60KVBrQ=@vger.kernel.org X-Gm-Message-State: AFuF++kTqH0FyW2bf6z7NIY5lSjiiyUtMiBXPAT0ezEcvMxoPYwu/IAH Flfg1C0tahzBfCIRik9e70s0LJPQFvk7dALKVC7Ro4nXs61W1U+BTSLXwYcGlIjrpP6HUd2rL+y 0aUEVCssx0Ik= X-Gm-Gg: AR+sD12isLsyamovs171aFCDJ1SqJFOGROLoj7/R42di+RYH65YOPkzdBv4ybzobHlR CDR4fYOl/e/4S0eSO9RNCySnhrYiKywH6MQrMwTZ4fBsyb6oRUClCoY46QxseITtJVG9QMu92Ly o0nzdxk5ZICIWIaIGfAHrVqVSryB5Kk9NOQ9aeJZIGIoXMAgeIiJAVTxkUcNwWeBZ3T/CZ99zm3 qTurMAuxSun9mNyqqDgO7dyvddmcjLGgZMsnC7XiIXRl58f8I56w/tLKdcZeXZFX5MjCzVtHWh6 ewjjpRS89dNMA1ceidT71HZ/ar4GEMJhc+gAgLwsbKnzJgBpETnKacb5UhOB+V1YlYHzp0q3whW 8oO/0E9LoDeUiKtP1ncDpBHt6TMkEp2vSX10+s+KabHzxIfeudFZdvoCDmJp2B9Ndv7Ldj4tsHY AtLaw5Yn66gUgA2ART+1a2rXQ3670/sxdr66TfTVAsut4kgcYnSWWIUimlmHhgz0ZH7H4Rl+lsD 7gnrtZf9C73qU5OTA== X-Received: by 2002:a05:600c:1f87:b0:49c:dadb:18a7 with SMTP id 5b1f17b1804b1-49ce5818132mr59943005e9.10.1788345747514; Wed, 02 Sep 2026 03:42:27 -0700 (PDT) Received: from debian12.ucl.ac.uk (eduroam-int-pat-8-79.ucl.ac.uk. [144.82.8.79]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-484492ce5e5sm5197521f8f.36.2026.09.02.03.42.26 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 02 Sep 2026 03:42:27 -0700 (PDT) From: Diego Oliva To: Paulo Alcantara , Namjae Jeon Cc: Ronnie Sahlberg , Shyam Prasad N , Tom Talpey , Bharath SM , linux-cifs@vger.kernel.org, samba-technical@lists.samba.org, linux-kernel@vger.kernel.org Subject: [PATCH v3 2/2] smb: client: reject out-of-bounds DataOffset in CIFSSMBRead() Date: Wed, 2 Sep 2026 11:42:07 +0100 Message-Id: <20260902104207.1820332-3-diego@bynar.io> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20260902104207.1820332-1-diego@bynar.io> References: <20260902104207.1820332-1-diego@bynar.io> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The SMB1 synchronous read helper CIFSSMBRead() validates the server's DataLength against CIFSMaxBufSize and the caller's count, but never validates DataOffset. The copy source is formed as &pSMBr->hdr.Protocol + le16_to_cpu(pSMBr->DataOffset) and memcpy()'d for DataLength bytes with no check that the [DataOffset, DataOffset + DataLength) range lies within the response actually received from the server. A malicious or compromised SMB1 server can return a response carrying an in-range DataLength and a large DataOffset, driving the source pointer past the end of the response buffer. The memcpy() then copies adjacent kernel heap into the caller's read buffer (information disclosure), or reads unmapped memory and oopses (denial of service). SMB1 is not negotiated by default; reaching this code requires an explicit vers=3D1.0 mount. Both DataOffset and the received response length recorded in rsp_iov.iov_len are relative to the start of the SMB header, so reject the response unless DataOffset + DataLength fits within that length, using overflow-safe arithmetic, before forming the source pointer. The response length has been validated by the previous patch, so the DataOffset and DataLength fields can be read safely here. While here, make data_length unsigned. It holds a length derived from unsigned on-the-wire fields and is only ever compared against unsigned quantities; print it with %u accordingly, and add __func__ to the cifs_dbg() calls in this function. smb_EIO2() was introduced in v6.19, so this does not apply to older stable trees without returning plain -EIO instead. Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") Cc: # 6.19.x Assisted-by: Bynario AI Signed-off-by: Diego Oliva --- fs/smb/client/cifssmb.c | 17 ++++++++++++----- fs/smb/client/trace.h | 1 + 2 files changed, 13 insertions(+), 5 deletions(-) diff --git a/fs/smb/client/cifssmb.c b/fs/smb/client/cifssmb.c index aa6b904ad866..3c86eb6cf76e 100644 --- a/fs/smb/client/cifssmb.c +++ b/fs/smb/client/cifssmb.c @@ -1728,7 +1728,8 @@ CIFSSMBRead(const unsigned int xid, struct cifs_io_pa= rms *io_parms, rsp_iov.iov_len, tcon->ses->server->vals->read_rsp_size); *nbytes =3D 0; } else { - int data_length =3D le16_to_cpu(pSMBr->DataLengthHigh); + unsigned int data_length =3D le16_to_cpu(pSMBr->DataLengthHigh); + __u16 data_offset =3D le16_to_cpu(pSMBr->DataOffset); data_length =3D data_length << 16; data_length +=3D le16_to_cpu(pSMBr->DataLength); *nbytes =3D data_length; @@ -1736,14 +1737,20 @@ CIFSSMBRead(const unsigned int xid, struct cifs_io_= parms *io_parms, /*check that DataLength would not go beyond end of SMB */ if ((data_length > CIFSMaxBufSize) || (data_length > count)) { - cifs_dbg(FYI, "bad length %d for count %d\n", - data_length, count); + cifs_dbg(FYI, "%s: bad length %u for count %u\n", + __func__, data_length, count); rc =3D smb_EIO2(smb_eio_trace_read_overlarge, data_length, count); *nbytes =3D 0; + } else if ((size_t)data_offset + data_length > rsp_iov.iov_len) { + /* check that the data lies within the received response */ + cifs_dbg(FYI, "%s: bad data offset %u length %u for response of %zu\n", + __func__, data_offset, data_length, rsp_iov.iov_len); + rc =3D smb_EIO2(smb_eio_trace_read_bad_offset, + data_offset, data_length); + *nbytes =3D 0; } else { - pReadData =3D (char *) (&pSMBr->hdr.Protocol) + - le16_to_cpu(pSMBr->DataOffset); + pReadData =3D (char *) (&pSMBr->hdr.Protocol) + data_offset; /* if (rc =3D copy_to_user(buf, pReadData, data_length)) { cifs_dbg(VFS, "Faulting on read rc =3D %d\n",rc); rc =3D -EFAULT; diff --git a/fs/smb/client/trace.h b/fs/smb/client/trace.h index 12241abb8e2e..b442cccd1530 100644 --- a/fs/smb/client/trace.h +++ b/fs/smb/client/trace.h @@ -79,6 +79,7 @@ EM(smb_eio_trace_qreparse_setup_count, "qreparse_setup_count") \ EM(smb_eio_trace_qreparse_sizes_wrong, "qreparse_sizes_wrong") \ EM(smb_eio_trace_qsym_bcc_too_small, "qsym_bcc_too_small") \ + EM(smb_eio_trace_read_bad_offset, "read_bad_offset") \ EM(smb_eio_trace_read_mid_state_unknown, "read_mid_state_unknown") \ EM(smb_eio_trace_read_overlarge, "read_overlarge") \ EM(smb_eio_trace_read_rsp_malformed, "read_rsp_malformed") \ --=20 2.39.5