From nobody Mon Sep 28 09:58:45 2026 Received: from mail-pf1-f181.google.com (mail-pf1-f181.google.com [209.85.210.181]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 34B4436B906 for ; Sun, 23 Aug 2026 16:07:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.181 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787501238; cv=none; b=SZav7whx57LhspwWTII9kQBX7fxs6LzEkXChsB2FrbDVnLUzSeg9h7J3qTSZcRQZcIwykqpM0vHxvU64YBRz/VzhfveUeNV08rCxOJAck9cWm4LWhPbYeWzVinYcj+r7svRDv2ZvGOBHJTxRPci85UP8WVKRluS0oAjaf0s1cws= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787501238; c=relaxed/simple; bh=WmRoR2qjdL0S4mdn9pkVY06GU4Q99k2G2O6p9GYRgmw=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Tm+Hg+4GsxGiyq4dj3o4dBTgDAvEnh3YhHoBZFvGiV5FTOlYfpESfi19apehjX1YUE6qSLFgj9xyGE/gWplB/oIYNSO4ptgiuvbn08ZOaB3ElXlg2gMPzyzkuWRppQCLs83vp3LkRSV7gbJzq1Nvx8x2Llk+QoTorUdMmjENgcY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=nebusec.ai; spf=pass smtp.mailfrom=nebusec.ai; dkim=pass (2048-bit key) header.d=nebusec.ai header.i=@nebusec.ai header.b=kSROMfAt; arc=none smtp.client-ip=209.85.210.181 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=nebusec.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=nebusec.ai Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=nebusec.ai header.i=@nebusec.ai header.b="kSROMfAt" Received: by mail-pf1-f181.google.com with SMTP id d2e1a72fcca58-84faf0fa17eso2658975b3a.2 for ; Sun, 23 Aug 2026 09:07:16 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nebusec.ai; s=google; t=1787501236; x=1788106036; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=mNgkMYHHXvaXh9ETBcwWCoDa3W5TTVRzmfpXC6Gf2Lg=; b=kSROMfAtIUVWsJkXiKZbfQRVzzD8j0viXKOlkngEU/dbsyOH7DX0uyV0LzAm6YWiPg FojawNGvnOAptF54vdqyy0WNlKZpYXvtWkSNCykA3fIxC3ARtJ3d7ac9ZftDFzfgl7pI HDbVXQ3uw8p3arnhAiMsrsMLdjFUmm/6nR/4mv0j+CKcxWN8TCoBss5fdG2DzROzCXnt 94uN2clQF8tjYfLO/Y5z5ZAjPb3YmgOxVRrVAQOOf2UAWVe0KauET/KyrrwRBF/9zZcm qtiAeBBdPH4gwlc5HANQgUkuRlBserf5JG5aEabpbyi/gaV0JCBGKCeXM0uVBDhr7cB4 w9fg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787501236; x=1788106036; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=mNgkMYHHXvaXh9ETBcwWCoDa3W5TTVRzmfpXC6Gf2Lg=; b=IFm/IW8ijUoWzZBS295HDisdBMQT2Y4xUc26sP/Q9PoQdFFTCX7x2Ttf3B3+tsp1My FRIcDTvSYgUS9UzrfKAO6tl3SUo+ArS/PFAqiB4nF68R+OPOwQMRnYpI7jsd1Tx6agqE T60CKskNAkYV39EQy1RSMTaEfXtajEef7TIrRAVbjAHXBDSVtAqeO1BjOK9sZCr22aET 1awsMo9+rjzePbDHa6YFi/GzaSL0fF54jc//McabHS1ZC1lHCx0LZS0kOfsPbSdRuQo+ YN0uoMiEfIpXO779tGwsp/QT/jzVh88wH9RxECKhx1eW5XsBrsZyWIaKVqNGXkzgNzdP lYjg== X-Forwarded-Encrypted: i=1; AHgh+RoUJp8sNygfItzCWCGgGBSc9NkCyEPywLLFFWiKxj3CKvq9IYLjZSGkv0WjSb9PrPzMnuxWpxSHuR6m6zk=@vger.kernel.org X-Gm-Message-State: AFuF++mjoHdmws2auIw8hPq/0P0lgMli00Y10Mc4EnHYvXXCv/WaCGhY 5FNCSXQjy3k7HiN73E7ypuPePf+hCEUxgiljlGBPjBp4xMnV0XjxvKy/ST7dhWAlEwzI X-Gm-Gg: AR+sD13o5SwC1vgsOwdoCDUnonP1/hsbdPZ1d1kxPklIlWd03IvlRPb+GUwu2Z8mWzS gBFUtmpHYx30WOXHwhfQ9TQtL3O5sHjekmHwNw5eqH0GDZ75n7eOzEVPpnBVmAnmHU6v0fcU5Q2 5B9jFACU3GPlw3fq9jwnEHu6pYsUtgcvVMHjPvx6rJ7shVkRXaS3a1R7VYVbRmiQAsixC7Rijcv DtADABuDRuODHgDEgm7W1v8TG0oYrlttpzqehX/j2Qek31FMx0GnMItfpNOySaoXMORctTjS2uC 9dvZPsVqydubhdmYt+BD3RGVSxpu9JunRBCcHW+9O+DLk9R2MwtkV/v/JkhpuBqyiqMNPZl4m2k /Bl9vOe0YNQSdvi7F2ilMtT7ETVDs7ABMp7jbW3wXx3/P1hyGm1USDP5LourpHTK+6FL87z3p07 7puqcyjXR2e5dw1S6B3PY0Zaq6OMmYKZ3dWrYcORRqvXy7th1HGuERBJCZyYTKU7T+pPlpYFpmV eTmmag15gYPGcc= X-Received: by 2002:a05:6a00:b42:b0:848:62ab:7b7 with SMTP id d2e1a72fcca58-8520be923e7mr20008268b3a.16.1787501236345; Sun, 23 Aug 2026 09:07:16 -0700 (PDT) Received: from gmail.com ([115.199.218.100]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-8520f14a418sm1211724b3a.47.2026.08.23.09.07.11 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 23 Aug 2026 09:07:15 -0700 (PDT) From: Zihan Xi To: Steve French Cc: linux-cifs@vger.kernel.org, samba-technical@lists.samba.org, linux-kernel@vger.kernel.org, Paulo Alcantara , Ronnie Sahlberg , Shyam Prasad N , Tom Talpey , Bharath SM , Pavel Shilovsky , Aurelien Aptel , stable@vger.kernel.org, Vega Subject: [PATCH v2 1/2] smb: client: fix create context out-of-bounds reads Date: Sun, 23 Aug 2026 16:06:28 +0000 Message-ID: <20260823160638.12198-1-zihanx@nebusec.ai> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" smb2_parse_contexts() validates the complete create-context area but does not bound each context record by its Next field before dispatching to a handler. A malformed chain can therefore expose bytes past one context to the handler. The QFid handler also used a full response-structure cast even though it only consumes DiskFileId. Bound each context by Next and reject malformed chains. Read the QFid DiskFileId only when the context data covers that field, and do not call the lease parser unless the record contains every field it reads, including LeaseFlags. Fixes: b8c32dbb0deb ("CIFS: Request SMB2.1 leases") Fixes: 89a5bfa350fa ("smb3: optimize open to not send query file internal i= nfo") Cc: stable@vger.kernel.org Reported-by: Vega Assisted-by: Codex:gpt-5.4 Signed-off-by: Zihan Xi --- changes in v2: - Bound each response context by Next and reject malformed chains. - Read QFid DiskFileId only when DataLength covers the payload. - Extend the SMB2 lease minimum through the LeaseFlags field. - Correct Fixes history for the pre-existing Next/lease path and the late= r QFid path. - v1 Link: https://lore.kernel.org/all/eb1bc35611f91bd10a4772400b37fac26f= 660956.1782579150.git.xizh2024@lzu.edu.cn/ --- fs/smb/client/smb2pdu.c | 38 ++++++++++++++++++++++++++++++++------ 1 file changed, 32 insertions(+), 6 deletions(-) diff --git a/fs/smb/client/smb2pdu.c b/fs/smb/client/smb2pdu.c index 4ce165e40657..95d862a1241b 100644 --- a/fs/smb/client/smb2pdu.c +++ b/fs/smb/client/smb2pdu.c @@ -2375,14 +2375,29 @@ create_reconnect_durable_buf(struct cifs_fid *fid) return buf; } =20 +static size_t smb2_create_lease_min_cc_len(struct TCP_Server_Info *server) +{ + if (server->vals->create_lease_size =3D=3D sizeof(struct create_lease_v2)) + return offsetof(struct create_lease_v2, lcontext.Epoch) + + sizeof(__le16); + return offsetof(struct create_lease, lcontext.LeaseFlags) + + sizeof(__le32); +} + static void parse_query_id_ctxt(struct create_context *cc, struct smb2_file_all_info *= buf) { - struct create_disk_id_rsp *pdisk_id =3D (struct create_disk_id_rsp *)cc; + u16 doff =3D le16_to_cpu(cc->DataOffset); + u32 dlen =3D le32_to_cpu(cc->DataLength); + u8 *beg; + + if (dlen < sizeof(__le64)) + return; =20 - cifs_dbg(FYI, "parse query id context 0x%llx 0x%llx\n", - pdisk_id->DiskFileId, pdisk_id->VolumeId); - buf->IndexNumber =3D pdisk_id->DiskFileId; + beg =3D (u8 *)cc + doff; + memcpy(&buf->IndexNumber, beg, sizeof(__le64)); + cifs_dbg(FYI, "parse query id context 0x%llx\n", + le64_to_cpu(buf->IndexNumber)); } =20 static void @@ -2430,6 +2445,7 @@ int smb2_parse_contexts(struct TCP_Server_Info *serve= r, struct smb2_create_rsp *rsp =3D rsp_iov->iov_base; struct create_context *cc; size_t rem, off, len; + size_t cc_len; size_t doff, dlen; size_t noff, nlen; char *name; @@ -2452,9 +2468,18 @@ int smb2_parse_contexts(struct TCP_Server_Info *serv= er, buf->IndexNumber =3D 0; =20 while (rem >=3D sizeof(*cc)) { + off =3D le32_to_cpu(cc->Next); + if (off) { + if ((off & 0x7) || off > rem || off < sizeof(*cc)) + return -EINVAL; + cc_len =3D off; + } else { + cc_len =3D rem; + } + doff =3D le16_to_cpu(cc->DataOffset); dlen =3D le32_to_cpu(cc->DataLength); - if (check_add_overflow(doff, dlen, &len) || len > rem) + if (check_add_overflow(doff, dlen, &len) || len > cc_len) return -EINVAL; =20 noff =3D le16_to_cpu(cc->NameOffset); @@ -2466,7 +2491,8 @@ int smb2_parse_contexts(struct TCP_Server_Info *serve= r, switch (nlen) { case 4: if (!strncmp(name, SMB2_CREATE_REQUEST_LEASE, 4)) { - *oplock =3D server->ops->parse_lease_buf(cc, epoch, + if (cc_len >=3D smb2_create_lease_min_cc_len(server)) + *oplock =3D server->ops->parse_lease_buf(cc, epoch, lease_key); } else if (buf && !strncmp(name, SMB2_CREATE_QUERY_ON_DISK_ID, 4)) { From nobody Mon Sep 28 09:58:45 2026 Received: from mail-pf1-f176.google.com (mail-pf1-f176.google.com [209.85.210.176]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 53F6738D3E6 for ; Sun, 23 Aug 2026 16:07:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.176 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787501251; cv=none; b=sjx2AxjJdGkknmrT2GKTPtPGB94xJmj8SNWlRxiL1IEgSLSJHkVOI7C940usWhBP0qo1StwHNmGWQWuzckOu26GPF20EePXpPWe3w/2EV8l0g0/OWxxYj1fSbs58UGU/4G+6uEKUFD201xEf5R8ldDV+QVZvJbmp1mywTCEoAZ0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787501251; c=relaxed/simple; bh=t47MXdoZVmA/0CIxHNFWECHyPwzjT/krdzHraaaG/vk=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=PFg/LWRAVBCXpFuNHc5+Uf+/dKe/3iYMOum5qz7IffKcT0WC6s/a5qrTFnZH6UVqVpw/Rc6kutVPi6YkXBE7akaZWWjlRdWUKLxPGB+E/oC41wTGdfrRIMUdKmSqM2GBY+jMs4/jTkJJuEeNz/wwZ8QtRY65PhfWF7VUiL+i51E= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=nebusec.ai; spf=pass smtp.mailfrom=nebusec.ai; dkim=pass (2048-bit key) header.d=nebusec.ai header.i=@nebusec.ai header.b=koGhxssg; arc=none smtp.client-ip=209.85.210.176 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=nebusec.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=nebusec.ai Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=nebusec.ai header.i=@nebusec.ai header.b="koGhxssg" Received: by mail-pf1-f176.google.com with SMTP id d2e1a72fcca58-8486ac3f347so3155716b3a.1 for ; Sun, 23 Aug 2026 09:07:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nebusec.ai; s=google; t=1787501250; x=1788106050; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=09gcrrpoB/ZfazZRgqzNGcQ8HoDldlLl2juqlWH2ddQ=; b=koGhxssg/iluLxS7rtZ1mwSpbH9fY4H+Is6cjd4Exwdy+yQ6AoTxktq92DlXpfrl+B BT1RnI6H1j0xxMhW7XjBBsK9ziZJTFW9p04R2cRL3OSsmjm10c8cAD4bP3ql/+nLpoFi Oa3IJzdlpKMoTaJHJ8jwQXENjUub8Xz2VHDoOz8QMTRnCoDxuZuSMEgPXCRnZpBCZJzc Vtheh3zKn0Qk9XANZTS8pkihhDyahgvU50tLjUfXdffdBSBdrCbh/srcW06nxaJgC+6L 0mk10VGmR8/3ttNeEOne6ROi+r8qSnWJmV692Kg0H4f1oJKiA48t7xOYCrtb7GDZf6KB NXSQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787501250; x=1788106050; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=09gcrrpoB/ZfazZRgqzNGcQ8HoDldlLl2juqlWH2ddQ=; b=RcvH7ozCN4xsod7CdL75P+15T//fRC4Z6yt8FFPJ7zhoxM2M2aeYppBgygPGBZuyul A9YrZ3h7sf1xGIwkoI2MZjgghgEODpfzVp5Dbgj9qnsV5yQJR64OOKRp8oXZ2BkxqhqP 1xXJIC2kMLXLTbHUcaxNF+XJetWKKja0r1u6owcBiA76V0mqaSDwvkhRgqCXGQzINoto /7iRyDuZsBh5UvgCvBAjh2u6Tx51jCtGAYil1AeAHr5rWjQxDrSugBnNAQPrl9szyW5D M8kHqSeoNIVzURO+sFquO1cfghxLzFa/0uufxy87UqfeMAN6yegIrdvG/fAtekOr7QBv 3OXg== X-Forwarded-Encrypted: i=1; AHgh+RpZjszb91eO4O1tLSGYniHeCGGVfHye0X+2QUvel/I3f0HhJEJWo2ecAoYSxeHqc6UsdQLwIF++N6GFqqs=@vger.kernel.org X-Gm-Message-State: AFuF++nmjxMYhWkx8cDrK3Npri8JLQDZNbPHjRe8N0kJ8K+9WlF5bNpN G0x11vr4CF+fJ6gDfZ2sL6KS91XVHkTSXIiLAvv0iME+S6TfcYSrUhklaFygrO15wnsBPibck+2 s3MV3ZDdznjQL9g== X-Gm-Gg: AR+sD11OUwuv4cbSkqFTSnf0/NkxR8nKUmUeCg7CzMrL1k3FvKIRvXxdrtGcUPIIwon GttqTK8qQehqMv5G29snmcKqWUF6AQOjE8sEDGYK//SzyU2jrGuVc83F3b12ozHTs70JbtmQceN bom8JZO5ZNBDISJ+w9G/yXchcQli9tP7msVoiXs1KUzpBmiCpJzi5U19+z0PThqkkvLf5zD8OKr L1PYPIP1f4O2HZTPCjp9Rgccj0INWxNnMpZIMuFtJdzTfz2KsySa+MFZ9rtAv9SuhpYL28PDvLc haups+JkisbpDBYtWTuCPfaxUCP1d585Sa6L1Rb42yK0fv0K8BN1UfVq9E4P8WaQ6717u21DOEP Co33QnkTPqmMCEi6ThG0PmdqNODBV2bCRNQVP0QdeeBejfFhNU0+lSVC5v1Gvd/pTTW8fW55/jh gQ5WuSwGHHUVaTjLQaYQBt5BolXmMDw8Of6Az4VYzeCjMOHct0VOPjf0ACDJKzRqSYX/FAAlgO6 e7vbcKjXtcu68FrvsPjQQ4SSi0= X-Received: by 2002:a05:6a00:300f:b0:851:8bde:7861 with SMTP id d2e1a72fcca58-851f9fa5b0bmr21741628b3a.1.1787501249566; Sun, 23 Aug 2026 09:07:29 -0700 (PDT) Received: from gmail.com ([115.199.218.100]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-8520f14a418sm1211724b3a.47.2026.08.23.09.07.24 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 23 Aug 2026 09:07:29 -0700 (PDT) From: Zihan Xi To: Steve French Cc: linux-cifs@vger.kernel.org, samba-technical@lists.samba.org, linux-kernel@vger.kernel.org, Paulo Alcantara , Ronnie Sahlberg , Shyam Prasad N , Tom Talpey , Bharath SM , Pavel Shilovsky , Aurelien Aptel , stable@vger.kernel.org, Vega Subject: [PATCH v2 2/2] smb: client: validate POSIX create context length Date: Sun, 23 Aug 2026 16:06:29 +0000 Message-ID: <20260823160638.12198-2-zihanx@nebusec.ai> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" parse_posix_ctxt() reads the fixed nlink, reparse-tag, and mode fields before checking that the POSIX create context contains them. A short context can pass the generic create-context checks and still make these fixed-width reads run past the declared data. Require the POSIX context data to cover the three fixed fields before reading them. Keep the handler's existing soft-failure behavior for malformed metadata so a bad optional context does not fail the open. Fixes: 69dda3059e7a ("cifs: add SMB2_open() arg to return POSIX data") Cc: stable@vger.kernel.org Reported-by: Vega Assisted-by: Codex:gpt-5.4 Signed-off-by: Zihan Xi --- changes in v2: - Add a handler-level DataLength check before reading the three fixed POS= IX fields. - Attribute the fixed-field read to the POSIX create-context introduction. - Preserve the existing soft-failure behavior for malformed optional meta= data. - v1 Link: https://lore.kernel.org/all/eb1bc35611f91bd10a4772400b37fac26f= 660956.1782579150.git.xizh2024@lzu.edu.cn/ --- fs/smb/client/smb2pdu.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/fs/smb/client/smb2pdu.c b/fs/smb/client/smb2pdu.c index 95d862a1241b..e3973d331633 100644 --- a/fs/smb/client/smb2pdu.c +++ b/fs/smb/client/smb2pdu.c @@ -2405,11 +2405,14 @@ parse_posix_ctxt(struct create_context *cc, struct = smb2_file_all_info *info, struct create_posix_rsp *posix) { int sid_len; + u32 dlen =3D le32_to_cpu(cc->DataLength); u8 *beg =3D (u8 *)cc + le16_to_cpu(cc->DataOffset); - u8 *end =3D beg + le32_to_cpu(cc->DataLength); + u8 *end =3D beg + dlen; u8 *sid; =20 memset(posix, 0, sizeof(*posix)); + if (dlen < 3 * sizeof(__le32)) + return; =20 posix->nlink =3D get_unaligned_le32(beg); posix->reparse_tag =3D get_unaligned_le32(beg + 4);