]> git.ipfire.org Git - thirdparty/kernel/stable-queue.git/commitdiff
Drop ksmbd-validate-compound-request-size-before-reading-.patch-18864
authorSasha Levin <sashal@kernel.org>
Thu, 30 Jul 2026 00:54:34 +0000 (20:54 -0400)
committerSasha Levin <sashal@kernel.org>
Thu, 30 Jul 2026 00:54:34 +0000 (20:54 -0400)
Signed-off-by: Sasha Levin <sashal@kernel.org>
queue-6.18/ksmbd-validate-compound-request-size-before-reading-.patch-18864 [deleted file]
queue-6.18/series

diff --git a/queue-6.18/ksmbd-validate-compound-request-size-before-reading-.patch-18864 b/queue-6.18/ksmbd-validate-compound-request-size-before-reading-.patch-18864
deleted file mode 100644 (file)
index 1c9d66a..0000000
+++ /dev/null
@@ -1,69 +0,0 @@
-From 2dfad88ad7f4d242e768910e27e636f8fb524a20 Mon Sep 17 00:00:00 2001
-From: Sasha Levin <sashal@kernel.org>
-Date: Mon, 13 Jul 2026 21:55:10 +0000
-Subject: ksmbd: validate compound request size before reading StructureSize2
-
-From: Xiang Mei (Microsoft) <xmei5@asu.edu>
-
-[ Upstream commit 15b38176fd1530372905c602fde51fe89ec8c877 ]
-
-When ksmbd validates a compound (chained) SMB2 request,
-ksmbd_smb2_check_message() reads pdu->StructureSize2 without first
-checking that the compound element is large enough to contain it.
-StructureSize2 is a 2-byte field at offset 64
-(__SMB2_HEADER_STRUCTURE_SIZE) from the start of each element.
-
-The compound-walking logic only guarantees that a full 64-byte SMB2
-header is present for the trailing element: when NextCommand is 0, len is
-reduced to the number of bytes remaining after next_smb2_rcv_hdr_off. A
-remote client can craft a compound request whose last element has exactly
-64 bytes, so the 2-byte StructureSize2 read at offset 64 extends one byte
-past the receive buffer, producing a slab-out-of-bounds read.
-
-  BUG: KASAN: slab-out-of-bounds in ksmbd_smb2_check_message (fs/smb/server/smb2misc.c:402)
-  Read of size 2 at addr ffff888012ae31ac by task kworker/0:1/14
-  The buggy address is located 172 bytes inside of allocated 173-byte region
-  Workqueue: ksmbd-io handle_ksmbd_work
-  Call Trace:
-   ...
-   kasan_report (mm/kasan/report.c:595)
-   ksmbd_smb2_check_message (fs/smb/server/smb2misc.c:402)
-   handle_ksmbd_work (fs/smb/server/server.c:119)
-   process_one_work (kernel/workqueue.c:3314)
-   worker_thread (kernel/workqueue.c:3397)
-   kthread (kernel/kthread.c:436)
-   ret_from_fork (arch/x86/kernel/process.c:158)
-   ret_from_fork_asm (arch/x86/entry/entry_64.S:245)
-
-Reject any compound element that is too small to hold StructureSize2
-before dereferencing it.
-
-Fixes: e2f34481b24d ("cifsd: add server-side procedures for SMB3")
-Reported-by: AutonomousCodeSecurity@microsoft.com
-Signed-off-by: Xiang Mei (Microsoft) <xmei5@asu.edu>
-Acked-by: Namjae Jeon <linkinjeon@kernel.org>
-Signed-off-by: Steve French <stfrench@microsoft.com>
-Signed-off-by: Sasha Levin <sashal@kernel.org>
----
- fs/smb/server/smb2misc.c | 5 +++++
- 1 file changed, 5 insertions(+)
-
-diff --git a/fs/smb/server/smb2misc.c b/fs/smb/server/smb2misc.c
-index b11d854d3fcfba..e07d9aad4319c5 100644
---- a/fs/smb/server/smb2misc.c
-+++ b/fs/smb/server/smb2misc.c
-@@ -405,6 +405,11 @@ int ksmbd_smb2_check_message(struct ksmbd_work *work)
-               return 1;
-       }
-+      if (len < __SMB2_HEADER_STRUCTURE_SIZE + sizeof(__le16)) {
-+              ksmbd_debug(SMB, "Message is too small for StructureSize2\n");
-+              return 1;
-+      }
-+
-       if (smb2_req_struct_sizes[command] != pdu->StructureSize2) {
-               if (!(command == SMB2_OPLOCK_BREAK_HE &&
-                   (le16_to_cpu(pdu->StructureSize2) == OP_BREAK_STRUCT_SIZE_20 ||
--- 
-2.53.0
-
index 915f5f2b4090a96d7878cc45e21396d75991c0a6..cc382a6b6f137ba94c38540a32bd307a052d3d61 100644 (file)
@@ -165,7 +165,6 @@ revert-drm-amd-display-add-missing-kdoc-for-allm-par.patch
 usb-xhci-pci-limit-via-vl805-dma-addressing-to-36-bi.patch
 selftests-bpf-adjust-verifier_map_ptr-for-the-map-s-.patch
 selftests-bpf-keep-verifier_map_ptr-exercising-ops-p.patch
-ksmbd-validate-compound-request-size-before-reading-.patch-18864
 wifi-ath9k-hif_usb-don-t-dereference-hif_dev-after-r.patch
 wifi-ath11k-fix-null-pointer-dereference-in-ath11k_h.patch
 hwmon-corsair-psu-stop-device-io-before-calling-hid_.patch