ksmbd: validate object id handles before response buffers

FSCTL_CREATE_OR_GET_OBJECT_ID requires a fixed-size output buffer, but an
invalid file handle must take precedence over output buffer validation.

Look up the handle before checking the available response buffer size. This
returns STATUS_FILE_CLOSED for a closed handle while preserving the buffer
size validation for valid handles.

Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
This commit is contained in:
Namjae Jeon 2026-07-12 14:31:02 +09:00
parent 8dd5ca858d
commit dd56221217

View File

@ -9615,17 +9615,18 @@ int smb2_ioctl(struct ksmbd_work *work)
struct file_object_buf_type1_ioctl_rsp *obj_buf;
struct ksmbd_file *fp;
if (out_buf_len < sizeof(struct file_object_buf_type1_ioctl_rsp)) {
ret = -EINVAL;
goto out;
}
fp = ksmbd_lookup_fd_fast(work, id);
if (!fp) {
ret = -EBADF;
rsp->hdr.Status = STATUS_FILE_CLOSED;
goto out2;
}
if (out_buf_len < sizeof(struct file_object_buf_type1_ioctl_rsp)) {
ksmbd_fd_put(work, fp);
ret = -EINVAL;
goto out;
}
ksmbd_fd_put(work, fp);
nbytes = sizeof(struct file_object_buf_type1_ioctl_rsp);