]> git.ipfire.org Git - thirdparty/linux.git/commit
cifs: validate idmap key payload length
authorLi Qiang <liqiang01@kylinos.cn>
Sat, 18 Jul 2026 16:22:27 +0000 (00:22 +0800)
committerSteve French <stfrench@microsoft.com>
Sun, 26 Jul 2026 22:40:20 +0000 (17:40 -0500)
commit455488cd5054bcc59db40fa1cc2c004031a5b2a5
tree985747f56872501a3f863253f4f80ff47d0519f2
parentaed0714255c80d143e9f6d4ae00ee14423204ad5
cifs: validate idmap key payload length

The cifs.idmap key type stores its payload length in key->datalen, which
is limited to U16_MAX.  Accepting a larger key payload truncates the
recorded length and can make later users interpret the payload using
inconsistent bounds.

Reject oversized preparsed payloads before allocating or copying them.
This keeps key->datalen consistent with the stored data for both inline
and separately allocated idmap payloads.

Signed-off-by: Li Qiang <liqiang01@kylinos.cn>
Signed-off-by: Steve French <stfrench@microsoft.com>
fs/smb/client/cifsacl.c