mirror of
https://github.com/torvalds/linux.git
synced 2026-09-12 04:23:03 +02:00
smb: client: reject userspace cifs.idmap descriptions
cifs.idmap key descriptions carry authority-bearing fields (owner and group SIDs and uid/gid values in "os:"/"gs:"/"oi:"/"gi:" form) that the cifs.idmap upcall helper treats as kernel-originating inputs. Unlike its sibling cifs.spnego, the cifs.idmap key type has no vet_description hook, so userspace can create keys of this type through request_key(2)/add_key(2) and supply those fields without CIFS origin. A request_key(2) call with a non-NULL callout then drives a root usermodehelper upcall (/sbin/request-key -> cifs.idmap) that consumes the unvetted description in root context. Only accept cifs.idmap descriptions while CIFS is using its private root_cred to request the key. id_to_sid()/sid_to_id() already run under override_creds(root_cred), so the kernel-originated path is unaffected. This mirrors commit3da1fdf4ef("smb: client: reject userspace cifs.spnego descriptions"), which applied the same restriction to cifs.spnego. Fixes:4d79dba0e0("cifs: Add idmap key and related data structures and functions (try #17 repost)") Reported-by: TencentOS Corvus AI <corvus@tencent.com> Cc: stable@vger.kernel.org Assisted-by: CodeBuddy:Kimi-K3 Signed-off-by: Aohan Mei <henrymei@tencent.com> Acked-by: David Howells <dhowells@redhat.com> Signed-off-by: Paulo Alcantara <pc@manguebit.org>
This commit is contained in:
parent
5be5bdda58
commit
d9d7eeb0ce
|
|
@ -100,8 +100,23 @@ cifs_idmap_key_destroy(struct key *key)
|
|||
kfree(key->payload.data[0]);
|
||||
}
|
||||
|
||||
static int
|
||||
cifs_idmap_key_vet_description(const char *description)
|
||||
{
|
||||
/*
|
||||
* cifs.idmap descriptions are authority-bearing inputs to the
|
||||
* cifs.idmap upcall helper. Only allow the kernel to create this
|
||||
* type of key using the private root_cred installed in
|
||||
* init_cifs_idmap; reject userspace request_key(2)/add_key(2).
|
||||
*/
|
||||
if (current_cred() != root_cred)
|
||||
return -EPERM;
|
||||
return 0;
|
||||
}
|
||||
|
||||
static struct key_type cifs_idmap_key_type = {
|
||||
.name = "cifs.idmap",
|
||||
.vet_description = cifs_idmap_key_vet_description,
|
||||
.instantiate = cifs_idmap_key_instantiate,
|
||||
.destroy = cifs_idmap_key_destroy,
|
||||
.describe = user_describe,
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user