From: Jeremy Allison Date: Tue, 5 Jan 2016 19:24:36 +0000 (-0800) Subject: CVE-2015-7560: s3: smbd: Refuse to get a POSIX ACL on a symlink. X-Git-Tag: samba-4.1.23~26 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=e3875621cec2b0a301be976331ade51baa087b68;p=thirdparty%2Fsamba.git CVE-2015-7560: s3: smbd: Refuse to get a POSIX ACL on a symlink. BUG: https://bugzilla.samba.org/show_bug.cgi?id=11648 Signed-off-by: Jeremy Allison Reviewed-by: Michael Adam --- diff --git a/source3/smbd/trans2.c b/source3/smbd/trans2.c index 5b008f53eb2..3fca8f2e2cc 100644 --- a/source3/smbd/trans2.c +++ b/source3/smbd/trans2.c @@ -5058,6 +5058,13 @@ NTSTATUS smbd_do_qfilepathinfo(connection_struct *conn, uint16 num_file_acls = 0; uint16 num_def_acls = 0; + status = refuse_symlink(conn, + fsp, + smb_fname->base_name); + if (!NT_STATUS_IS_OK(status)) { + return status; + } + if (fsp && fsp->fh->fd != -1) { file_acl = SMB_VFS_SYS_ACL_GET_FD(fsp, talloc_tos());