Re: [PATCH v3] smb: client: reject a tree connect response whose byte count is too small
From: Namjae Jeon
Date: Fri Aug 21 2026 - 11:08:53 EST
On Fri, Aug 21, 2026 at 9:36 PM Bryam Vargas via B4 Relay
<devnull+hexlabsecurity.proton.me@xxxxxxxxxx> wrote:
>
> From: Bryam Vargas <hexlabsecurity@xxxxxxxxx>
>
> CIFSTCon() bounds its strnlen() over the byte area with the server's
> ByteCount minus two, which for ByteCount 0 or 1 goes negative as an int
> and converts to a huge size_t. The later subtraction wraps the __u16
> bytes_left, and that is what bounds cifs_strndup_from_utf16(): a bound of
> up to 65535 against a ~16 KB cifs_req_poolp object runs off the end of the
> slab object, and the bytes reach userspace through tcon->nativeFileSystem
> in /proc/fs/cifs/DebugData.
>
> Reject a byte area too small for what the parser consumes. Two bytes is
> the least it can consume, and no conformant response carries fewer. The
> new trace point is the 129th smb_eio_trace entry, which __mode(byte)
> cannot represent, so the attribute goes with it.
>
> Fixes: cc20c031bb06 ("cifs: convert CIFSTCon to use new unicode helper functions")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Bryam Vargas <hexlabsecurity@xxxxxxxxx>
Reviewed-by: Namjae Jeon <linkinjeon@xxxxxxxxxx>
Thanks.