From nobody Sat Sep 26 04:30:09 2026 Received: from mail-pg1-f173.google.com (mail-pg1-f173.google.com [209.85.215.173]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A3D704A4988 for ; Fri, 4 Sep 2026 14:05:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.173 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788530736; cv=none; b=mEDHs/KN5hkpjK4uxIIjUrCqevXTkg5Frnt3K6X+QDijOZdwAkFjleorXkEC5TV5iXfom1AJypPgH42yloGnk30Vq7FnQBJIs3iHqTyOnjsxygC8G9Mg0822zsj85YWtCV+LpThujEYa2I8btwoExOIpdBQ/KtXQP/HPyJmEp6g= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788530736; c=relaxed/simple; bh=+tEmWFfrfMdfpRXuM7sJq5Jr/CVlm0Na5b7RR7FV7cc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=lwzgnABAhLeCoOqRyZS+W76IjO3+tU3CmqqZ3C/JQfGciuX+aZK0aMkaowCCFtAIJ504YRrrzZ7F7I2RxQwc31d3+i9sku9LqIegJ3Yh3Mb0ut8et79ghApOvGrG+tNoxT6HJJcgoWbH0FlULNU+tc/c4X3+y58Sp4hsx+tqvqA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=nebusec.ai; spf=pass smtp.mailfrom=nebusec.ai; dkim=pass (2048-bit key) header.d=nebusec.ai header.i=@nebusec.ai header.b=kQ8b+rBZ; arc=none smtp.client-ip=209.85.215.173 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=nebusec.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=nebusec.ai Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=nebusec.ai header.i=@nebusec.ai header.b="kQ8b+rBZ" Received: by mail-pg1-f173.google.com with SMTP id 41be03b00d2f7-cc1c3c90074so936900a12.2 for ; Fri, 04 Sep 2026 07:05:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nebusec.ai; s=google; t=1788530733; x=1789135533; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=hgCC47razGo0X63UNJ31Wa6CvgVCTBYXfU0eNJWGEdg=; b=kQ8b+rBZWjVH7Jaagy1LAZqyHANFlhxxvdjAa84AZVSDhx79LuBjVF49/4veDcEkwo zuf4JRd5fmJgrN5nkJL3odYU4GYNcDZ1114ZljV/d6dIx5HDmw2vlwDz2BFaMoAAg0yh SKhXs3VAaqIBIHZY5YVY3lRwDsn+h3h+Ar89Syg7fEj+0TqOIyqCeS5zWGykVZ3wIkN2 jr9HhOv5/6Mai9E8GhSb8LUcnd6BZ1lXk019z+9HKsV+sRv45DYTgxo0RtdyeWqkMtsa ostBRAbLVtgRLdbI7ao5zkLJgqkNdCEYy/qaCTdXAqPJNFfj2JXkNpdY9W+m6qgXqRUN QWgA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788530733; x=1789135533; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=hgCC47razGo0X63UNJ31Wa6CvgVCTBYXfU0eNJWGEdg=; b=TqmNAcT/lPxslk4uSDmPF3MWvwN6DTA5VUTi7YEylZkoS3ipUwDKFtt1S6sXKIZ12s oAS6I5lLXUVKZdk7UQuX+tLAnU4UoLjwDzuEVpJ/fz/PfJJ3ew9wY5l61lPcTlVSsrlA iODUto9YZ93cxkC7Z7EVLhB6gAhKj8Me8W8+TkZeTvLv2ckmxlgpGlJox/rnmHn0Pc9y vWRD0x/9v1/l6zfNqINGOKZbVrnFo3dv2KezUBn0ZSddlNfeHf3joRxRFAUdOemQOjWa sWCpEzN6t3zJ4mdXYaN3gyzCDtJsI7pI93Fg15/kLfv9tkQNZMe82wuG9MuYRfVKJozt D9RQ== X-Forwarded-Encrypted: i=1; AKwUvBzdHCQAgew3c7VZnim/XgLi+bHrDuTNdXWrLyDDS6NoqhSlu4n7P3HxN3YvxJX6pTir5gt5zA4IEi1TFI0=@vger.kernel.org X-Gm-Message-State: AFuF++kZ77JpcJTkrNgOgAe08fDLuZgrfTrc4+6tWvWf3b0pdwvgMXND ZIoQWs+NJpv7Sw4T82Ify5Xs4kv91YLuiuem5A04RjwVBDZ9P3d7C2T8LxbIAPyM4dad X-Gm-Gg: AYBFou3vjH726gSvsieJ/fKwK5lA9vY8CFRMwDWUZvtt5fktHiDFE9sQuhrxlqoD6ao HD57T+LMRCpVI87JDAfaVyZ8hm6Gl07geEaG/LY661I/AeSTVey0Po3tLHq8D8Qm79ZOFfkMrPV ni6G80iW0pgXP9gA9qM5gQPMhKv/ayXVAlA6+g7ub+bqesz0NTLajlNuAZLV8o8MtojELrrPhna v8bju7oln6XjgN2zcvz68f7vXoke9ij2mHbePSM/9uZmLz/m07gJKqpXwm3GfF2PJCYiVWMUVM8 VzZycfmy5rBK6RzR7klpAmMulEvgdnlDtrOVwh8T+yDISe3VRc36wEJ3LKMQKWUDMrxEcn3LglO Ddx7uxoZncqLhVfCEnFdGU5QmAmv0bsiVSAOk1FZ0aLruz0R6swfYtYqpHLFl/oi9n2z0Mqcpf3 euw/3F0nTnUNTTSjIa66rZFBI7/+sT29mhSBqZ7GXaTv2MQAUZ2l522QZvECFjjYczHab4yTlxy jiJSFUWY/zaUKdPRdk= X-Received: by 2002:a05:6a00:1405:b0:846:de21:3da4 with SMTP id d2e1a72fcca58-86168e8abc9mr7624230b3a.3.1788530731778; Fri, 04 Sep 2026 07:05:31 -0700 (PDT) Received: from b6ad5085b32f.. ([122.51.212.64]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-86153e3ac30sm1165524b3a.56.2026.09.04.07.05.27 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 04 Sep 2026 07:05:31 -0700 (PDT) From: Zihan Xi To: Steve French Cc: Zihan Xi , Paulo Alcantara , Ronnie Sahlberg , Shyam Prasad N , Tom Talpey , Bharath SM , Pavel Shilovsky , Aurelien Aptel , linux-cifs@vger.kernel.org, samba-technical@lists.samba.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH v3 1/2] smb: client: fix create context out-of-bounds reads Date: Fri, 4 Sep 2026 14:05:17 +0000 Message-ID: <20260904140527.62354-1-zihanx@nebusec.ai> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" smb2_parse_contexts() validates the complete create-context area but does not bound each context record by its Next field before dispatching to a handler. A malformed chain can therefore expose bytes past one context to the handler. The QFid handler also used a full response-structure cast even though it only consumes DiskFileId. Bound each context by Next and reject malformed chains. Read the QFid DiskFileId only when the context data covers that field, and do not call the lease parser unless the record contains every field it reads, including LeaseFlags. Fixes: b8c32dbb0deb ("CIFS: Request SMB2.1 leases") Fixes: 89a5bfa350fa ("smb3: optimize open to not send query file internal i= nfo") Cc: stable@vger.kernel.org Reported-by: Vega Assisted-by: LLM Signed-off-by: Zihan Xi --- changes in v3: - Resend after no response on v2; no functional code changes. - v2 Link: https://lore.kernel.org/all/cover.1787486936.git.zihanx@nebuse= c.ai/ changes in v2: - Bound each response context by Next and reject malformed chains. - Read QFid DiskFileId only when DataLength covers the payload. - Extend the SMB2 lease minimum through the LeaseFlags field. - Correct Fixes history for the pre-existing Next/lease path and the late= r QFid path. - v1 Link: https://lore.kernel.org/all/eb1bc35611f91bd10a4772400b37fac26f= 660956.1782579150.git.xizh2024@lzu.edu.cn/ --- fs/smb/client/smb2pdu.c | 38 ++++++++++++++++++++++++++++++++------ 1 file changed, 32 insertions(+), 6 deletions(-) diff --git a/fs/smb/client/smb2pdu.c b/fs/smb/client/smb2pdu.c index 4ce165e40657f..95d862a1241be 100644 --- a/fs/smb/client/smb2pdu.c +++ b/fs/smb/client/smb2pdu.c @@ -2375,14 +2375,29 @@ create_reconnect_durable_buf(struct cifs_fid *fid) return buf; } =20 +static size_t smb2_create_lease_min_cc_len(struct TCP_Server_Info *server) +{ + if (server->vals->create_lease_size =3D=3D sizeof(struct create_lease_v2)) + return offsetof(struct create_lease_v2, lcontext.Epoch) + + sizeof(__le16); + return offsetof(struct create_lease, lcontext.LeaseFlags) + + sizeof(__le32); +} + static void parse_query_id_ctxt(struct create_context *cc, struct smb2_file_all_info *= buf) { - struct create_disk_id_rsp *pdisk_id =3D (struct create_disk_id_rsp *)cc; + u16 doff =3D le16_to_cpu(cc->DataOffset); + u32 dlen =3D le32_to_cpu(cc->DataLength); + u8 *beg; + + if (dlen < sizeof(__le64)) + return; =20 - cifs_dbg(FYI, "parse query id context 0x%llx 0x%llx\n", - pdisk_id->DiskFileId, pdisk_id->VolumeId); - buf->IndexNumber =3D pdisk_id->DiskFileId; + beg =3D (u8 *)cc + doff; + memcpy(&buf->IndexNumber, beg, sizeof(__le64)); + cifs_dbg(FYI, "parse query id context 0x%llx\n", + le64_to_cpu(buf->IndexNumber)); } =20 static void @@ -2430,6 +2445,7 @@ int smb2_parse_contexts(struct TCP_Server_Info *serve= r, struct smb2_create_rsp *rsp =3D rsp_iov->iov_base; struct create_context *cc; size_t rem, off, len; + size_t cc_len; size_t doff, dlen; size_t noff, nlen; char *name; @@ -2452,9 +2468,18 @@ int smb2_parse_contexts(struct TCP_Server_Info *serv= er, buf->IndexNumber =3D 0; =20 while (rem >=3D sizeof(*cc)) { + off =3D le32_to_cpu(cc->Next); + if (off) { + if ((off & 0x7) || off > rem || off < sizeof(*cc)) + return -EINVAL; + cc_len =3D off; + } else { + cc_len =3D rem; + } + doff =3D le16_to_cpu(cc->DataOffset); dlen =3D le32_to_cpu(cc->DataLength); - if (check_add_overflow(doff, dlen, &len) || len > rem) + if (check_add_overflow(doff, dlen, &len) || len > cc_len) return -EINVAL; =20 noff =3D le16_to_cpu(cc->NameOffset); @@ -2466,7 +2491,8 @@ int smb2_parse_contexts(struct TCP_Server_Info *serve= r, switch (nlen) { case 4: if (!strncmp(name, SMB2_CREATE_REQUEST_LEASE, 4)) { - *oplock =3D server->ops->parse_lease_buf(cc, epoch, + if (cc_len >=3D smb2_create_lease_min_cc_len(server)) + *oplock =3D server->ops->parse_lease_buf(cc, epoch, lease_key); } else if (buf && !strncmp(name, SMB2_CREATE_QUERY_ON_DISK_ID, 4)) { --=20 2.43.0 From nobody Sat Sep 26 04:30:09 2026 Received: from mail-pf1-f172.google.com (mail-pf1-f172.google.com [209.85.210.172]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 890CE4A2A79 for ; Fri, 4 Sep 2026 14:05:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.172 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788530739; cv=none; b=GoJ0Zqt+ToVU7oY9ratftUtbFJam0662+L6lNg+TUOW5tS4zazDaJr9LjwunfonTC/nn4p9ZZThxAFgdcIthTsk1cm9vI5rqp+04a46VSfrEcHEVIh7sujVz6Yy/HV7X7uiq0u77Q8reHHkHuINx7iJXi9nStD8yv9YQ1ZqNCwI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788530739; c=relaxed/simple; bh=74j3fwyacQITliuGsMZlTzpkrfqOUEWVeCXeNha+g+w=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=rwVC1Q8FP0li8q7sAETXrRW1gcGqiT4pl39qOuu+qKRakznQmd/1+P93EHBkMirc6j/vWD1TGGbPs7CzA4RmFb+OAMPA/Oit2p0sTpLWQtn7WRFzlKr9LmnJGRaqWFwLbI9w/CPJyHfkjWzYa7SStC7R3uv2O+CVw9klxmfEe5w= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=nebusec.ai; spf=pass smtp.mailfrom=nebusec.ai; dkim=pass (2048-bit key) header.d=nebusec.ai header.i=@nebusec.ai header.b=S/aOp+/K; arc=none smtp.client-ip=209.85.210.172 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=nebusec.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=nebusec.ai Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=nebusec.ai header.i=@nebusec.ai header.b="S/aOp+/K" Received: by mail-pf1-f172.google.com with SMTP id d2e1a72fcca58-84fa3b14ee1so843730b3a.0 for ; Fri, 04 Sep 2026 07:05:38 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nebusec.ai; s=google; t=1788530738; x=1789135538; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Set7xBiEVWYLIBwmw99LbgzIL/a2lqsWrI9NiV/oNhw=; b=S/aOp+/KlipcPJE4avbEo+Qd8kMLK/sKuvTE8ai/yTh1MsPb9KKh9sSRaYkgyV7GKR EAevDulyr7dCvgeNZQWjfSIJUwO7bS4BW9U5Qy1YSq2fS8jf/15ylscPD4CELTldr3k0 LUVeqx/lSyjZWxQk2ttPXXOcWa2k4FkefoebKqGbO7AVCFq9eFw4IkvqvFSFjS4LXJYO VRsy8EriuZZxgV8z1PcHMtA8YAKsUENxaFYv3pzy+GOmzgTgC1oFjlufkqeZMSmsm7v4 PibPhvj5leqqxK+9wpOPfRFsCseP94Ff0ns54MByfWONlr9mSzOijVvhkyegVp1pNQ39 e8BQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788530738; x=1789135538; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=Set7xBiEVWYLIBwmw99LbgzIL/a2lqsWrI9NiV/oNhw=; b=LvRmKcHS4fMD33Kjhv+C7T8ONSHHq8EC2ZF/WHoMychCVAiPYiKXXku5s+8shx671T /LvwXJg7SSy2JoVTzv/amXYL9LhgWfHfyHbo7kv/h5hv/b3yFHsJIp8egTW8wG7AZkW4 wQAG6tMdif7evnJ023UAjwlUOo/RiE39B/9InM2TWDmrOfPFzpVQe0+82wFunOKTDWfw AQGb1fqvWoij/RTz08GqFqKrR7/0dqEGYa5Z4v38jTmMgIqj5gsMM1BiLQWRz+LgSF8r FCvY9w1v7OauH7Vl2xBdrACnt/3Ikd2UavprwlU6ESl0BbW0HWWF+0mj7Aa1fTjhuPJP mJUg== X-Forwarded-Encrypted: i=1; AKwUvBzWjBntwkeGcN56O6sCXKKHEdFmk49ePip7IGr5a1on6T5iYKZA707q3G9aB+9Qqaefnlmi9PYUQgP5Euk=@vger.kernel.org X-Gm-Message-State: AFuF++nUVFo8s3L6i6+0gJrluvufufG1oDTojAtRotSzk+2f1A0m7YOB c3Rh4CNS9O9FKHmJ0WpjP8zmrTMMGl25j7x609vZ9qgWEscan681gtmKkIrIEsxWg2wV X-Gm-Gg: AYBFou1gXZoDEdiNto8IC+GXK+PJ/wjgkW/KL1+Lz0CswkIVF+OtIs1PHgp774SQeig soLVQ1Vj5ScCjxWHlOm3AouAzSFoytjqV1li5cFprG6OGSt17XikOVyOCmNpfubpnsIgvPoKdzr KR647aCZdkT9M2bOPLl5t2X4PXQ8iL+p0xqF3mCo4MsvTaHx3ftAcV1XFVtCRCuYcvSMll5Omzz Yw3mEca9dResV3ljbYZV/nCAg2VZ1es6kow/pclig3L1vONKiq1RLqOo9H7TWO7qDHE8tVohviC igXIur9H8T02wMUj8C3rX6A1nWoLgwHJTkf5pFCrd+hXXq3GDHofaMaNA58kHmZU0hFuA89CKAw MEseitvXML6NzOzNeVCxdZiLQeYCsRaA+eZP5ycu2taiaFYOeFevAOxNq4Ef7T+eBjJIEVE6grE U2GuUJmJw0wuIUnD8IiwJ2hPT16rEymGpQ31lTeiO/yFK7gL0p98MKXchQnjXmUycIV4W+DnhTt DedZ0e2yi8NQ8himy8= X-Received: by 2002:a05:6a00:f04:b0:851:ba04:ca02 with SMTP id d2e1a72fcca58-8616a36cc48mr9997364b3a.16.1788530736532; Fri, 04 Sep 2026 07:05:36 -0700 (PDT) Received: from b6ad5085b32f.. ([122.51.212.64]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-86153e3ac30sm1165524b3a.56.2026.09.04.07.05.32 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 04 Sep 2026 07:05:36 -0700 (PDT) From: Zihan Xi To: Steve French Cc: Zihan Xi , Paulo Alcantara , Ronnie Sahlberg , Shyam Prasad N , Tom Talpey , Bharath SM , Pavel Shilovsky , Aurelien Aptel , linux-cifs@vger.kernel.org, samba-technical@lists.samba.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH v3 2/2] smb: client: validate POSIX create context length Date: Fri, 4 Sep 2026 14:05:18 +0000 Message-ID: <20260904140527.62354-2-zihanx@nebusec.ai> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" parse_posix_ctxt() reads the fixed nlink, reparse-tag, and mode fields before checking that the POSIX create context contains them. A short context can pass the generic create-context checks and still make these fixed-width reads run past the declared data. The current in-tree smb2_open_file() path passes a NULL posix pointer, so this handler is not reached on ordinary open. Still require the POSIX context data to cover the three fixed fields before reading them, because the helper itself performs those unguarded reads. Keep the handler's existing soft-failure behavior for malformed metadata so a bad optional context does not fail the open. Fixes: 69dda3059e7a ("cifs: add SMB2_open() arg to return POSIX data") Cc: stable@vger.kernel.org Reported-by: Vega Assisted-by: LLM Signed-off-by: Zihan Xi --- changes in v3: - Resend after no response on v2; no functional code changes. - v2 Link: https://lore.kernel.org/all/cover.1787486936.git.zihanx@nebuse= c.ai/ changes in v2: - Add a handler-level DataLength check before reading the three fixed POS= IX fields. - Attribute the fixed-field read to the POSIX create-context introduction. - Preserve the existing soft-failure behavior for malformed optional meta= data. - v1 Link: https://lore.kernel.org/all/eb1bc35611f91bd10a4772400b37fac26f= 660956.1782579150.git.xizh2024@lzu.edu.cn/ --- fs/smb/client/smb2pdu.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/fs/smb/client/smb2pdu.c b/fs/smb/client/smb2pdu.c index 95d862a1241be..e3973d331633d 100644 --- a/fs/smb/client/smb2pdu.c +++ b/fs/smb/client/smb2pdu.c @@ -2405,11 +2405,14 @@ parse_posix_ctxt(struct create_context *cc, struct = smb2_file_all_info *info, struct create_posix_rsp *posix) { int sid_len; + u32 dlen =3D le32_to_cpu(cc->DataLength); u8 *beg =3D (u8 *)cc + le16_to_cpu(cc->DataOffset); - u8 *end =3D beg + le32_to_cpu(cc->DataLength); + u8 *end =3D beg + dlen; u8 *sid; =20 memset(posix, 0, sizeof(*posix)); + if (dlen < 3 * sizeof(__le32)) + return; =20 posix->nlink =3D get_unaligned_le32(beg); posix->reparse_tag =3D get_unaligned_le32(beg + 4); --=20 2.43.0