mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 01:32:21 +02:00
ksmbd: reject undersized decompressed SMB2 requests
ksmbd_decompress_request() bounds the decompressed size only against
the maximum request size. A compression transform can therefore
produce a buffer smaller than an SMB2 PDU and install it as
conn->request_buf.
The receive path subsequently calls ksmbd_smb_request(), which reads
the protocol ID before the normal SMB2 minimum-size check. If the
decompressed output is too short, that read can access beyond the
request allocation.
Require the decompressed output to contain at least a complete minimum
SMB2 PDU before allocating and installing the replacement request
buffer.
Fixes: a08de24c2b ("ksmbd: negotiate and decode SMB2 compression")
Cc: stable@vger.kernel.org
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
This commit is contained in:
parent
cfc0b8e508
commit
5e1b924808
|
|
@ -56,7 +56,8 @@ int ksmbd_decompress_request(struct ksmbd_conn *conn)
|
|||
}
|
||||
|
||||
max_allowed_pdu_size = SMB3_MAX_MSGSIZE + conn->vals->max_write_size;
|
||||
if (out_size > max_allowed_pdu_size ||
|
||||
if (out_size < sizeof(struct smb2_pdu) ||
|
||||
out_size > max_allowed_pdu_size ||
|
||||
out_size > MAX_STREAM_PROT_LEN)
|
||||
return -EINVAL;
|
||||
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user