]> git.ipfire.org Git - thirdparty/kernel/stable.git/commit
cifs: parse_dfs_referrals: prevent oob on malformed input
authorEugene Korenevsky <ekorenevsky@aliyun.com>
Mon, 13 Oct 2025 18:39:30 +0000 (21:39 +0300)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 29 Oct 2025 13:04:30 +0000 (14:04 +0100)
commitcfacc7441f760e4a73cc71b6ff1635261d534657
tree64bf64cce0a96fe11b99d7495383342c3dcbe48d
parent4f4b9ca73f84130d9fbb0fc02306ce94ce8bdbe6
cifs: parse_dfs_referrals: prevent oob on malformed input

commit 6447b0e355562a1ff748c4a2ffb89aae7e84d2c9 upstream.

Malicious SMB server can send invalid reply to FSCTL_DFS_GET_REFERRALS

- reply smaller than sizeof(struct get_dfs_referral_rsp)
- reply with number of referrals smaller than NumberOfReferrals in the
header

Processing of such replies will cause oob.

Return -EINVAL error on such replies to prevent oob-s.

Signed-off-by: Eugene Korenevsky <ekorenevsky@aliyun.com>
Cc: stable@vger.kernel.org
Suggested-by: Nathan Chancellor <nathan@kernel.org>
Acked-by: Paulo Alcantara (Red Hat) <pc@manguebit.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
fs/smb/client/misc.c