mirror of
https://github.com/torvalds/linux.git
synced 2026-10-07 11:06:03 +02:00
ksmbd: validate object id handles before response buffers
FSCTL_CREATE_OR_GET_OBJECT_ID requires a fixed-size output buffer, but an invalid file handle must take precedence over output buffer validation. Look up the handle before checking the available response buffer size. This returns STATUS_FILE_CLOSED for a closed handle while preserving the buffer size validation for valid handles. Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
This commit is contained in:
parent
8dd5ca858d
commit
dd56221217
|
|
@ -9615,17 +9615,18 @@ int smb2_ioctl(struct ksmbd_work *work)
|
|||
struct file_object_buf_type1_ioctl_rsp *obj_buf;
|
||||
struct ksmbd_file *fp;
|
||||
|
||||
if (out_buf_len < sizeof(struct file_object_buf_type1_ioctl_rsp)) {
|
||||
ret = -EINVAL;
|
||||
goto out;
|
||||
}
|
||||
|
||||
fp = ksmbd_lookup_fd_fast(work, id);
|
||||
if (!fp) {
|
||||
ret = -EBADF;
|
||||
rsp->hdr.Status = STATUS_FILE_CLOSED;
|
||||
goto out2;
|
||||
}
|
||||
|
||||
if (out_buf_len < sizeof(struct file_object_buf_type1_ioctl_rsp)) {
|
||||
ksmbd_fd_put(work, fp);
|
||||
ret = -EINVAL;
|
||||
goto out;
|
||||
}
|
||||
ksmbd_fd_put(work, fp);
|
||||
|
||||
nbytes = sizeof(struct file_object_buf_type1_ioctl_rsp);
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user