mirror of
https://github.com/torvalds/linux.git
synced 2026-09-11 20:13:02 +02:00
ksmbd: initialize FileSystemControlFlags in FS_CONTROL_INFORMATION
smb2_get_info_filesystem() reports 48 bytes for FS_CONTROL_INFORMATION,
that is the whole of struct smb2_fs_control_info, but never assigns
FileSystemControlFlags. Those four bytes go to the client as they are
found in the response buffer.
The buffer is zeroed on allocation, so a standalone request leaks
nothing. A compound request can leak: the offset of the next response
is advanced by the length pinned for the previous one, so a reply that
was written into the buffer and then dropped in favour of the short
error response of smb2_set_err_rsp() stays there, and the next reply is
laid over it with only the header cleared.
ksmbd does not implement quota tracking, so report no control flags.
Fixes: e2f34481b2 ("cifsd: add server-side procedures for SMB3")
Cc: stable@vger.kernel.org
Signed-off-by: Aleksandr Khromov <haa@amicon.ru>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
This commit is contained in:
parent
399aa12450
commit
c0cd3fc682
|
|
@ -7500,6 +7500,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
|
|||
info->FreeSpaceStopFiltering = 0;
|
||||
info->DefaultQuotaThreshold = cpu_to_le64(SMB2_NO_FID);
|
||||
info->DefaultQuotaLimit = cpu_to_le64(SMB2_NO_FID);
|
||||
info->FileSystemControlFlags = 0;
|
||||
info->Padding = 0;
|
||||
rsp->OutputBufferLength = cpu_to_le32(48);
|
||||
fixed_len = 48;
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user