From nobody Fri Sep 25 13:55:22 2026 Received: from mail-wm1-f51.google.com (mail-wm1-f51.google.com [209.85.128.51]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A503E35E95A for ; Fri, 11 Sep 2026 14:58:42 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.51 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789138725; cv=none; b=MhkKs1aMo3uiBj6ynsqdfW8hQmf1jRD1+6o2Wo41yLA/HZBuT8IRBjXAmn2kqdZMpU1Exfjg2AiG8Va4yNff8yFdCKa0rUW2mj535iLdtmT48prKcYHPg5ydJxWLuFTArYrDHGbbUmmYUJl3VY03O+iWjgszQuRreBUjon/MdQE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789138725; c=relaxed/simple; bh=6U2KyYESRummjrFiAB7QS+VzeYDYkDkZ1bo7japatKc=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=n+Fuvbs9AMk8OXv1++ZwXBiJCooEW8FsRMVhymD6hSTE65rIgwANIXhZG2KhNWIFyhhVUE43fyrbqOV9DDu7DsxOmBMpOj01wE2J8Bkr+jyYdcpq7OKuo2vjqzJHqoEOrekOkE3qIQOFq5D08uTajg514kbEM7Rp5xKi/Uwq2FI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=bynar.io; spf=pass smtp.mailfrom=bynar.io; dkim=pass (2048-bit key) header.d=bynar.io header.i=@bynar.io header.b=FrDbkANP; arc=none smtp.client-ip=209.85.128.51 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=bynar.io Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=bynar.io Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=bynar.io header.i=@bynar.io header.b="FrDbkANP" Received: by mail-wm1-f51.google.com with SMTP id 5b1f17b1804b1-4998b5a63e2so11288855e9.1 for ; Fri, 11 Sep 2026 07:58:42 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=bynar.io; s=google; t=1789138719; x=1789743519; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=QJDLLy3mcgmNCllNfuwiuaOIAc//JDOWE+yHQCqzUAQ=; b=FrDbkANP9Qg8oSbW+WZDxccE5+J/bhYgR/69T65UIPo62HSvAPD4t4MiP6YiCRcbxj CWqmNPBcqelM4IfqdbYw6BksGk+bw89lJecmM8tOlJt/RBvVadZdkpf5cRqlHZHIyeTY gQefWPH8Zpr9Er+iZC2gZjK/Ib3q9dyw6KFDGKR1ymG9athpbeMn5ICkE8gYyi24x/iD 3/JBykkCl2jUu6CsEM81MBjWdBXE8hpbwKa14fZP+zluhfmeORDMREwLp2cohSfbzn8d cm8cZ9jDbm3Scv1K+uYBcPdYrPhFTIbUIsZQIUOLU9F3aQdG1rbFom3692Cl+h1ZMvVg Fqzw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789138719; x=1789743519; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=QJDLLy3mcgmNCllNfuwiuaOIAc//JDOWE+yHQCqzUAQ=; b=WjG5X/APEhFU67DWG8xKiiLfT7s4c2Dqr22Jwmahkdxyidy3At45uWnwRbRiXGkXy5 koNiuPrPWcmwZnsToqoivAcdwuSvD8zCcMz6OIKaonkU0ZNEo6vI8dBw29kjWYx9qz3Q 67YqF2uxW46Iep5W3I7Ud1ecQeKDzC+FkeXm/jhxsrQtYrULLaiz5NFkk8PYDvw9+8GM A2Er4d6Ho0356C2fYEPBgFEIoLzZfxlxHWvmJ1NF2ePbyMWJzdcHEo80p4NdjiT36r2V HT//iBaCtuJi+9VV9pn7FYZ+NW/h4KbeaAQ2WwrLfIyFbjG2g64ge9LSzBFcOV0Wwaud evxQ== X-Forwarded-Encrypted: i=1; AKwUvBwkOTihWzyrn3+I1HP8VdQTLjvmEL4U5xuSiOuBJMtGc+qsSt59Z5i4tnFX9gvhJSv+w2YE2zr/RzBvIQo=@vger.kernel.org X-Gm-Message-State: AFuF++muKS+L84jwIba7Taxq3GrJLw5Ell1YTgeYKQRR6IzLGweRGwkC yA+eq/eSCAtQAW9DSIovypc+3NUemeaakNNH0TdBRzSHwaajoPBe6srsTi5axsZeXIHz X-Gm-Gg: AYBFou1FHlG2tUO6AQ1QOxrpHEDpEak5xermEVph/K5Tx1sPZ9UbmYZfN3a0hla18yF G8EkBqmDqwV2qKYJdg5W4GUJErI3nYlnWbmlP+HtKKovSDNP+yo1pyPhAp1yYQGLXPwd5RXyYNG evMSpLy79Qox2w7VHGlKsBWuGpdAM2SLva/T+t3nIb9K9gSdzRg8JjZ5Bi9PUHn1K+TKRun/Hp1 P0LieTvqupsU7iWsH9rlW6lJPPj/uwKMFMZ9xoSxFIXLLuybGcSnidxzm/2zqzIZ2eeYlfCn6JI 12MN90F6PkysYTYPLP7FZtCCke7Gr3llDQoAlqQ0pacwcELUkIpYBa6dRKhzcFo1oc3/WQl+pfy 5lQiB8Yv2xJRq6C1fBagYHcnERr/wI+WLnwqkzBR9bRKbRdEIWCW5dgCPsjcCY0RVAR3UdV7izD MLoLqaRrHozAiaPThxx8D1Zd+17qJJzYJy2JVqQr+NFlHaHGNau7Mp8UILoX6lmZxMPfRGvT1+M 30uII9hKn8u9aHiFInliMWeK5Kt X-Received: by 2002:a05:600c:4fc8:b0:49c:cedc:3c36 with SMTP id 5b1f17b1804b1-49e619bd0femr54492545e9.16.1789138719577; Fri, 11 Sep 2026 07:58:39 -0700 (PDT) Received: from debian12.ucl.ac.uk (eduroam-int-pat-8-79.ucl.ac.uk. [144.82.8.79]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49e61a81943sm50432915e9.1.2026.09.11.07.58.38 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 11 Sep 2026 07:58:39 -0700 (PDT) From: Diego Oliva To: Paulo Alcantara , Namjae Jeon , linux-cifs@vger.kernel.org Cc: Ronnie Sahlberg , Shyam Prasad N , Tom Talpey , Bharath SM , David Howells , Jeff Layton , samba-technical@lists.samba.org, linux-kernel@vger.kernel.org Subject: [PATCH 1/3] smb: client: reject short WRITE responses in the SMB1 write paths Date: Fri, 11 Sep 2026 15:57:56 +0100 Message-Id: <20260911145758.3833254-2-diego@bynar.io> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20260911145758.3833254-1-diego@bynar.io> References: <20260911145758.3833254-1-diego@bynar.io> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" cifs_writev_callback(), CIFSSMBWrite() and CIFSSMBWrite2() all read Count and CountHigh out of the WRITE_RSP returned by the server without first checking that a whole WRITE_RSP was actually received. The length of the response is available to each of them, in mid->response_pdu_len, bytes_returned and rsp_iov.iov_len respectively, but none of them constrains it to be at least sizeof(WRITE_RSP) before those fields are dereferenced. In the asynchronous case cifs_check_receive() has run first, but it only verifies the signature and maps the SMB error; it performs no length validation. A malicious or compromised SMB1 server can therefore return a response shorter than the WRITE_RSP header and still have it parsed. In CIFSSMBWrite() the response buffer is the request buffer, since smb_init() hands out a single allocation for both, so the count is read back out of the request that was just sent; in the other two the reply lives in the demultiplex thread's buffer, so it comes from recycled slab memory. Either way the client reports a number of bytes written that the server never sent. SMB1 is not negotiated by default; reaching this code requires an explicit vers=3D1.0 mount. Reject the response unless it is at least sizeof(WRITE_RSP) bytes long. This cannot reject a conforming server: WRITE_RSP is documented as wct =3D 6, so the smallest valid reply is sizeof(struct smb_hdr) + 2 * 6 + 2, which is sizeof(WRITE_RSP). Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") Fixes: c28c89fc43e3 ("cifs: add cifs_async_writev") Cc: # 6.19.x Assisted-by: Bynario AI Signed-off-by: Diego Oliva --- fs/smb/client/cifssmb.c | 21 +++++++++++++++++++++ fs/smb/client/trace.h | 1 + 2 files changed, 22 insertions(+) diff --git a/fs/smb/client/cifssmb.c b/fs/smb/client/cifssmb.c index f9aff0712794..b1525d491ce5 100644 --- a/fs/smb/client/cifssmb.c +++ b/fs/smb/client/cifssmb.c @@ -1880,6 +1880,12 @@ CIFSSMBWrite(const unsigned int xid, struct cifs_io_= parms *io_parms, cifs_stats_inc(&tcon->stats.cifs_stats.num_writes); if (rc) { cifs_dbg(FYI, "Send error in write =3D %d\n", rc); + } else if (bytes_returned < (int)sizeof(WRITE_RSP)) { + /* check that the received response can hold a whole WRITE_RSP */ + cifs_dbg(FYI, "%s: server returned short header. got=3D%d expected=3D%zu= \n", + __func__, bytes_returned, sizeof(WRITE_RSP)); + rc =3D smb_EIO2(smb_eio_trace_write_rsp_short, + bytes_returned, sizeof(WRITE_RSP)); } else { *nbytes =3D le16_to_cpu(pSMBr->CountHigh); *nbytes =3D (*nbytes) << 16; @@ -1927,6 +1933,15 @@ cifs_writev_callback(struct TCP_Server_Info *server,= struct mid_q_entry *mid) if (result !=3D 0) break; =20 + if (mid->response_pdu_len < sizeof(WRITE_RSP)) { + /* check that the received response can hold a whole WRITE_RSP */ + cifs_dbg(FYI, "%s: server returned short header. got=3D%u expected=3D%z= u\n", + __func__, mid->response_pdu_len, sizeof(WRITE_RSP)); + result =3D smb_EIO2(smb_eio_trace_write_rsp_short, + mid->response_pdu_len, sizeof(WRITE_RSP)); + break; + } + written =3D le16_to_cpu(smb->CountHigh); written <<=3D 16; written +=3D le16_to_cpu(smb->Count); @@ -2150,6 +2165,12 @@ CIFSSMBWrite2(const unsigned int xid, struct cifs_io= _parms *io_parms, } else if (resp_buf_type =3D=3D 0) { /* presumably this can not happen, but best to be safe */ rc =3D smb_EIO1(smb_eio_trace_write_bad_buf_type, resp_buf_type); + } else if (rsp_iov.iov_len < sizeof(WRITE_RSP)) { + /* check that the received response can hold a whole WRITE_RSP */ + cifs_dbg(FYI, "%s: server returned short header. got=3D%zu expected=3D%z= u\n", + __func__, rsp_iov.iov_len, sizeof(WRITE_RSP)); + rc =3D smb_EIO2(smb_eio_trace_write_rsp_short, + rsp_iov.iov_len, sizeof(WRITE_RSP)); } else { WRITE_RSP *pSMBr =3D (WRITE_RSP *)rsp_iov.iov_base; *nbytes =3D le16_to_cpu(pSMBr->CountHigh); diff --git a/fs/smb/client/trace.h b/fs/smb/client/trace.h index b442cccd1530..a0ad8068425e 100644 --- a/fs/smb/client/trace.h +++ b/fs/smb/client/trace.h @@ -150,6 +150,7 @@ EM(smb_eio_trace_write_bad_buf_type, "write_bad_buf_type") \ EM(smb_eio_trace_write_mid_state_unknown, "write_mid_state_unknown") \ EM(smb_eio_trace_write_rsp_malformed, "write_rsp_malformed") \ + EM(smb_eio_trace_write_rsp_short, "write_rsp_short") \ E_(smb_eio_trace_write_too_far, "write_too_far") =20 #define smb3_rw_credits_traces \ --=20 2.39.5 From nobody Fri Sep 25 13:55:22 2026 Received: from mail-wm1-f49.google.com (mail-wm1-f49.google.com [209.85.128.49]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8B206218EBA for ; Fri, 11 Sep 2026 14:58:42 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.49 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789138726; cv=none; b=PgA2VwC6K1TM59DxvppLgJ28OETVeWQHp4qhX0mFgQ5aht/cW18Ew8TldvqXv/Tl//lyavN7PFDMTmGuAO4ahAuf08D2NOf3HsqB23tI9bGRXOjWDnyS0xyjUZPq0kyHMH+q+eSXyMuktsWW0pSx0ZV11znDwDGe2cShQCwz7Cw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789138726; c=relaxed/simple; bh=6jxEmCc9BbzZCj2ZjVAnnfuYinsXrMRzEkJk2RpGm5c=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=sZ27Oplnp7vn0lu0EuQuh1dJTFp97aevBgugvCezA+jtmpY0bx3mxAAUZF0VLR7K5qgkvqffymDj5zs68wOAzM+fWDAbhbRuHf/Aeo6OIPh5dkhp/2WtXCGP/uvUkta+sKOpaLvtpCH2ET0IDxmKNFF8PXVwnTffYklrm2M2dPI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=bynar.io; spf=pass smtp.mailfrom=bynar.io; dkim=pass (2048-bit key) header.d=bynar.io header.i=@bynar.io header.b=To4NoGSr; arc=none smtp.client-ip=209.85.128.49 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=bynar.io Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=bynar.io Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=bynar.io header.i=@bynar.io header.b="To4NoGSr" Received: by mail-wm1-f49.google.com with SMTP id 5b1f17b1804b1-49a97714f5dso9343915e9.0 for ; Fri, 11 Sep 2026 07:58:42 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=bynar.io; s=google; t=1789138720; x=1789743520; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=gO79o8tBFz05lhoujECcqggmTdIRnVTc3ftGgS6FHds=; b=To4NoGSramyZn2rPg4LhsWi+XDAMsW/zmb90hWzICmYqNHTGHCdRRXEquznrDXxvkw 3mM4UBNdsIhYU9BNDHfqn6xSs0ACAnofSY8HRb+Nye16hbYv0+VQPa18LLzr4GCVcImz 2Qek7sMRwY+iC/3TaC+nurWYgBxj7q+rzQ01q1vHi/e4mNy1gZepxSQagUJZ/YpoCv5Y mXVEAflYDYo3wYDEdK+MdPXTD3dl89CJYOUVILNXubVNdGaYQany1p4qK5g4OtTWX2Vl GtLKbVfgrsdFT58gAkHD88uZsFQLAGAOHsbGUImTpCSiWyhC8JpXERjihzL2q2ZZITIS XYYA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789138720; x=1789743520; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=gO79o8tBFz05lhoujECcqggmTdIRnVTc3ftGgS6FHds=; b=re6pNcJhqFw1MDOgRkDYo3WV6qCRx8f/WVTybvrZMQA9ci0pAw8gLVZ98LsFcN69Rj ea0Vz0GNLutTfpXbmXRcmm4RZYVLmIEUqsBcSkGxlMsMNMjeW6bxcxbIj4/6S7HZMoqg W5VH1q3jckmNYKp4fIiWGTOLsrO/5L3qWBqLwSybwPSUXnsDBOmEWBXgjDU/MnyNRWnM fhLXVSndkOuWHomxHcuxeUgXsAN5DQpijZmu7nP0FExExjTlOvqEs5KVuIYLWigfOIcZ Ldsr2Nul0TlGrpbhAsGJoQnu5MaA7HnxI0jhg8Y1ll0gv+mfEIq3kk8VsL4Yednt39BN rFsQ== X-Forwarded-Encrypted: i=1; AKwUvBwILZzUCEijq8F9UIY8ImehLDoqgMprcxpkRadz/8QJxd2DsGhoCjuaScj6oIDidGNSZrdeKvAAIPjkm10=@vger.kernel.org X-Gm-Message-State: AFuF++lKuNTYZj4cuku/8lMiLrGc1dlhARGDgiX2mFRDUgB/8oB4i1VJ Y/9FjF7aDO07mofGxbp2E63qmUxsGnEUBRVfokTCTbcr8MmHf46gVO0UEudy0VrliuHb X-Gm-Gg: AYBFou3Hl5II66vkjxdjY58w/GvJlf/IKFombpv1nn1S+dP/VVEgPYB9k5G5cvHQwRI pgZ6+XbxF2kqEjsqARE86v2MZtWICHYix8Ck6ycek5xC0ilBwVvbkv7B2nKibx98RAf3cvfY24F 3j3M/i65nVJF+gnzT4i6t/bBLXSPXMSbRLFVOznJXvOdI8i1gnQHvmjB99fi+rM9591jJTubrZ3 R1qiSxlTbUXPdGkqkXtMKOJinJwQFBYDhHr7qQ9LJl43j6gjf3sVPK9jY18+/VJfTkhvWCRDIUR mD8hflecMWa3cHmfGwDxFUJlfXevR0yh77bqAOLh61aLIjn8AA4eJT8qPGdOCIbKDugTeFgsTYu KpVn2JT8tRH6QrP9AJdW5/urTHe0OdxvacqEnPenEb7GXJYNm6NVCqFKeA1C8QiSDGUMndWb6+w 4B0jAPhEE40A/QqREXLtu+x8hZwrHDzqqbCPkI1pgZMSoqP3WQJS23vmPcBaHXJiEJXpVZ2rb+c jtjFo85AEs32P6K3+1A8idvHyj5Tt23i6NdLr8= X-Received: by 2002:a05:600c:3145:b0:49c:eb04:1c49 with SMTP id 5b1f17b1804b1-49e619906e4mr58147405e9.13.1789138720372; Fri, 11 Sep 2026 07:58:40 -0700 (PDT) Received: from debian12.ucl.ac.uk (eduroam-int-pat-8-79.ucl.ac.uk. [144.82.8.79]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49e61a81943sm50432915e9.1.2026.09.11.07.58.39 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 11 Sep 2026 07:58:40 -0700 (PDT) From: Diego Oliva To: Paulo Alcantara , Namjae Jeon , linux-cifs@vger.kernel.org Cc: Ronnie Sahlberg , Shyam Prasad N , Tom Talpey , Bharath SM , David Howells , Jeff Layton , samba-technical@lists.samba.org, linux-kernel@vger.kernel.org Subject: [PATCH 2/3] smb: client: reject over-long write counts in cifs_writev_callback() Date: Fri, 11 Sep 2026 15:57:57 +0100 Message-Id: <20260911145758.3833254-3-diego@bynar.io> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20260911145758.3833254-1-diego@bynar.io> References: <20260911145758.3833254-1-diego@bynar.io> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" cifs_writev_callback() builds the number of bytes written from the CountHigh and Count fields of the WRITE_RSP. Some servers are known to set CountHigh incorrectly, so the value is masked with 0xFFFF when it exceeds the requested length, but that only clears the high 16 bits: a Count that is on its own larger than the requested length survives the mask unchanged. written > wdata->subreq.len then still holds, the "written < wdata->subreq.len" test is false, and the inflated count is passed on as the result of the subrequest. netfs_write_subrequest_terminated() rejects that with a WARN(). A server answering a two-byte write with Count =3D 0xFFFF gives: ------------[ cut here ]------------ Subreq excess write: R=3D7[1] 65535 > 2 - 0 WARNING: fs/netfs/write_collect.c:508 at netfs_write_subrequest_terminated= +0x425/0x720, CPU#0: cifsd/79 CPU: 0 UID: 0 PID: 79 Comm: cifsd Not tainted 7.3.0-rc2-00131-g0a96d0d726c= d #45 PREEMPT(lazy) RIP: 0010:netfs_write_subrequest_terminated+0x43a/0x720 Call Trace: cifs_writev_callback+0x4af/0x900 cifs_demultiplex_thread+0xd35/0x2280 kthread+0x315/0x410 ret_from_fork+0x647/0x920 ret_from_fork_asm+0x1a/0x30 ---[ end trace 0000000000000000 ]--- so such a server triggers a kernel warning on every write, and a panic on a kernel built with panic_on_warn. Before netfs clamps the value, cifs_write_subrequest_terminated() has already used it to compute wrend, which feeds netfs_resize_file() and cifs_update_i_blocks_for_write(), so the size the client believes the file has also grows past what was actually written. SMB1 is not negotiated by default; reaching this code requires an explicit vers=3D1.0 mount. The missing upper bound dates from the introduction of cifs_writev_callback(). It became a WARN, and began inflating the client's idea of the file size, only once the write result was handed to netfs. Reject the response instead. A server reporting more written than it was asked to write is violating the protocol, and CIFSSMBRead() already treats the symmetric case on the read side as an error. Fixes: c28c89fc43e3 ("cifs: add cifs_async_writev") Fixes: 3ee1a1fc3981 ("cifs: Cut over to using netfslib") Cc: # 6.19.x Assisted-by: Bynario AI Signed-off-by: Diego Oliva --- fs/smb/client/cifssmb.c | 9 +++++++++ fs/smb/client/trace.h | 1 + 2 files changed, 10 insertions(+) diff --git a/fs/smb/client/cifssmb.c b/fs/smb/client/cifssmb.c index b1525d491ce5..30b9621664e8 100644 --- a/fs/smb/client/cifssmb.c +++ b/fs/smb/client/cifssmb.c @@ -1954,6 +1954,15 @@ cifs_writev_callback(struct TCP_Server_Info *server,= struct mid_q_entry *mid) if (written > wdata->subreq.len) written &=3D 0xFFFF; =20 + if (written > wdata->subreq.len) { + /* check that the server did not write more than requested */ + cifs_dbg(FYI, "%s: bad count %zu for length %zu\n", + __func__, written, wdata->subreq.len); + result =3D smb_EIO2(smb_eio_trace_write_overlarge, + written, wdata->subreq.len); + break; + } + if (written < wdata->subreq.len) { result =3D -ENOSPC; } else { diff --git a/fs/smb/client/trace.h b/fs/smb/client/trace.h index a0ad8068425e..a1c0cb1a5833 100644 --- a/fs/smb/client/trace.h +++ b/fs/smb/client/trace.h @@ -149,6 +149,7 @@ EM(smb_eio_trace_user_iter, "user_iter") \ EM(smb_eio_trace_write_bad_buf_type, "write_bad_buf_type") \ EM(smb_eio_trace_write_mid_state_unknown, "write_mid_state_unknown") \ + EM(smb_eio_trace_write_overlarge, "write_overlarge") \ EM(smb_eio_trace_write_rsp_malformed, "write_rsp_malformed") \ EM(smb_eio_trace_write_rsp_short, "write_rsp_short") \ E_(smb_eio_trace_write_too_far, "write_too_far") --=20 2.39.5 From nobody Fri Sep 25 13:55:22 2026 Received: from mail-wm1-f49.google.com (mail-wm1-f49.google.com [209.85.128.49]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 616E924BBEE for ; Fri, 11 Sep 2026 14:58:44 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.49 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789138728; cv=none; b=SIudvlbnSE/TZR9pXLkzUUS94vTcz2ez0DLQ8058W74WmNqd2ILUqWhgbSX4PP+94UEwIDKWEDf4o2sN5KySJODialIoM/jWNuOnrAkuuwAK/vlkJXpgZNQuaPbIFA/3X3xJWmU68/SpQFXh+nGSLqYJRULDWcSyb/UrMrPfFxw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789138728; c=relaxed/simple; bh=tXun5SzxalV9Hzmv86f5QD4391irUID86zoYreFOlLc=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=tC2oTvYXuBXzZ+fC6J9P0C6YA1SC3mR2fZc67wx3Qm7J/us+BPQNXm7LjGea9NJWbkZUbWMgXMgaPknxWCd7odXKYKDGPUtB4aAgKwbysYR4Y2j/YlTJRlajMXcWMEtsGE2Ay0r5XWwQaeD3SsBMBn2Ym5azBWEeXwYujwzkCkk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=bynar.io; spf=pass smtp.mailfrom=bynar.io; dkim=pass (2048-bit key) header.d=bynar.io header.i=@bynar.io header.b=aT8XxGWa; arc=none smtp.client-ip=209.85.128.49 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=bynar.io Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=bynar.io Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=bynar.io header.i=@bynar.io header.b="aT8XxGWa" Received: by mail-wm1-f49.google.com with SMTP id 5b1f17b1804b1-49e668491f3so3546285e9.1 for ; Fri, 11 Sep 2026 07:58:44 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=bynar.io; s=google; t=1789138723; x=1789743523; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=RlzncFxui7IWSYNS6TVWMZnw5flt5qN9CiLy90tWUhs=; b=aT8XxGWaA1H4lwsjLIrOGR34L1TRsXsLwfDZPfjDZsCnAhxvtAmXoCuQYKhj0O7oKG Der4jnrnt9qzb7URDLOLQMJjhVVJPQnFpBkECBaxaa93JxgMceitSOjfyH5+vZdwLtCg jOt8oKSoB8PkXcms94QCwyzKqUCgIbifnbpsGlRMQgkIUTSTCclYPRveDUWttSgfPz1B j/rUEO+obIEETotNHBuJRqU470D3LQquybYKTdJ4XOijs3CPcbrkNVhMxFUsXFOPExjB /qjVWVHgeKyo4Q8M/koMNwQ/4wnKUsmPdfGSmh7knKGJaO9M5NAyFGzXdzThtoNZsPxW hq+Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789138723; x=1789743523; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=RlzncFxui7IWSYNS6TVWMZnw5flt5qN9CiLy90tWUhs=; b=B2ENfDh1hxhUTWdwOxPphxdEqdOfe75FIcmhvDgRsZLEETbIzwOGR7fPh+RN6KRC6H Q+n46c3LBdp1l+wnaKmZRkcHOLt4Mhdr/U+30Vf+QZCJ8ubobtcS9ACCyn0rWMJ1PgnP 1mCtSdiWvBTJJtJ2QUhPsXC3AWzBfttalNCWxehl7vLPJTV7P65DGejYE//QfXL3QhrZ VqXetzKFotqEbL+8PQ5RqAWRdJhfzCRyFZPGaapd8KuaiN/aKyC4sBtLRmhjN3MY72Nx CRgHYWJHAD3mAX3mwTocmaQdM0URzJiyYTiKSRNilZyc284bqw2q+kc3R3dZy5kn44XP E8Vw== X-Forwarded-Encrypted: i=1; AKwUvBwhvhkeivFDC+8jHrSuOhJAcSlpl+50iZjT2GPwqNy+L2NHXThq5Zi5ygCR/43LCmKzvQ2QGksi6OdlCjE=@vger.kernel.org X-Gm-Message-State: AFuF++nmElE/kCOYHF5Qc8gLL3tTf1IK01t/7vg2haJrGIEdzH55Pm+d ClJ0iGTSdOi56kydgTZvns/1QWxYHTzzrb7XKLeg3OyfQxAvepUJN6Tqg61rQPVMNAI2 X-Gm-Gg: AYBFou1mFsuAKWXqdHZvy8ckqtZ5whpb6I0BL6ymzF4IVlCfzvnrroGQmxBkqboar5+ NnIZuHrWJG/FPaja/A/9JHFFdryUujS5ABm8XERgFS3OAyHjvKtvT8y7/QpIGMhzVtRplz4Tlzp yOHQ62cXuGZjE2dR6SY6vbq+XjrO828OLoQ2Bqxh29A92/G0rUqiPQoWUPa03kHJ48hUKX0qIGz C0iXnPVAU7WuCHmIhWQTyHuOvsPmlldbuWV6Gk/AYqOzqnK436zQRGTSb0jMIYWSWwZo6GX2Vgp CmsgYh0tx7VaQls21kkTq9zoaLTBsaEeWXUWR5zO4cfpx5EtsaapMn2HzGfNXu3SDU3nKhnlmXI K09m1XPo+7EFKuGaTw81pcfOta554oAgpY8NATDNNNgPiLXcQwzrhbMxK9BHanIi8Z8Xz+OGrL2 FRLgKR3as0HLkZdu0auFlkW3Q/wuJX+oVJj3OlWZ6g8KPOa5nU6Ov9WJ7INLmwlXfOpvSoEa1fb pd/JdNKtgGulZcVKm0549g5IpFX X-Received: by 2002:a05:600d:8648:10b0:49d:1f10:8b9f with SMTP id 5b1f17b1804b1-49e619836aemr42807155e9.7.1789138721935; Fri, 11 Sep 2026 07:58:41 -0700 (PDT) Received: from debian12.ucl.ac.uk (eduroam-int-pat-8-79.ucl.ac.uk. [144.82.8.79]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49e61a81943sm50432915e9.1.2026.09.11.07.58.40 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 11 Sep 2026 07:58:40 -0700 (PDT) From: Diego Oliva To: Paulo Alcantara , Namjae Jeon , linux-cifs@vger.kernel.org Cc: Ronnie Sahlberg , Shyam Prasad N , Tom Talpey , Bharath SM , David Howells , Jeff Layton , samba-technical@lists.samba.org, linux-kernel@vger.kernel.org Subject: [PATCH 3/3] smb: client: reject short responses in SMBQueryInformation() Date: Fri, 11 Sep 2026 15:57:58 +0100 Message-Id: <20260911145758.3833254-4-diego@bynar.io> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20260911145758.3833254-1-diego@bynar.io> References: <20260911145758.3833254-1-diego@bynar.io> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" SMBQueryInformation() reads attr, last_write_time and size out of the QUERY_INFORMATION_RSP returned by the server without first checking that a whole QUERY_INFORMATION_RSP was actually received. The length of the response is recorded in bytes_returned, but nothing constrains it to be at least sizeof(QUERY_INFORMATION_RSP) before those fields are dereferenced. A malicious or compromised SMB1 server can return a reply as short as 35 bytes, a header carrying WordCount and ByteCount of zero, which checkSMB() accepts because the calculated size matches the length received. last_write_time and size then lie beyond the received data. smb_init() hands out a single allocation for both the request and the response, so those fields are read back out of the request that was just sent, and a timestamp and file size synthesised from the path name end up in the inode and are reported by stat(). SMB1 is not negotiated by default; reaching this code requires an explicit vers=3D1.0 mount. Reject the response unless it is at least sizeof(QUERY_INFORMATION_RSP) bytes long. This cannot reject a conforming server: the response is documented as wct =3D 10, so the smallest valid reply is sizeof(struct smb_hdr) + 2 * 10 + 2, which is sizeof(QUERY_INFORMATION_RSP). Fixes: 6b8edfe0f918 ("[CIFS] Support for mounting to older servers part 2. = Add support for legacy getattr (lookup).") Cc: # 6.19.x Assisted-by: Bynario AI Signed-off-by: Diego Oliva --- fs/smb/client/cifssmb.c | 6 ++++++ fs/smb/client/trace.h | 1 + 2 files changed, 7 insertions(+) diff --git a/fs/smb/client/cifssmb.c b/fs/smb/client/cifssmb.c index 30b9621664e8..aad1c866d8e1 100644 --- a/fs/smb/client/cifssmb.c +++ b/fs/smb/client/cifssmb.c @@ -4068,6 +4068,12 @@ SMBQueryInformation(const unsigned int xid, struct c= ifs_tcon *tcon, (struct smb_hdr *) pSMBr, &bytes_returned, 0); if (rc) { cifs_dbg(FYI, "Send error in QueryInfo =3D %d\n", rc); + } else if (bytes_returned < (int)sizeof(QUERY_INFORMATION_RSP)) { + /* check that the received response can hold a whole rsp */ + cifs_dbg(FYI, "%s: server returned short header. got=3D%d expected=3D%zu= \n", + __func__, bytes_returned, sizeof(QUERY_INFORMATION_RSP)); + rc =3D smb_EIO2(smb_eio_trace_qinfo_rsp_short, + bytes_returned, sizeof(QUERY_INFORMATION_RSP)); } else if (data) { struct timespec64 ts; __u32 time =3D le32_to_cpu(pSMBr->last_write_time); diff --git a/fs/smb/client/trace.h b/fs/smb/client/trace.h index a1c0cb1a5833..6926a62ddb05 100644 --- a/fs/smb/client/trace.h +++ b/fs/smb/client/trace.h @@ -71,6 +71,7 @@ EM(smb_eio_trace_qfsinfo_bcc_too_small, "qfsinfo_bcc_too_small") \ EM(smb_eio_trace_qfsposixinfo_bcc_too_small, "qfsposixinfo_bcc_too_small"= ) \ EM(smb_eio_trace_qfsunixinfo_bcc_too_small, "qfsunixinfo_bcc_too_small") \ + EM(smb_eio_trace_qinfo_rsp_short, "qinfo_rsp_short") \ EM(smb_eio_trace_qpathinfo_bcc_too_small, "qpathinfo_bcc_too_small") \ EM(smb_eio_trace_qpathinfo_invalid, "qpathinfo_invalid") \ EM(smb_eio_trace_qreparse_data_area, "qreparse_data_area") \ --=20 2.39.5