Re: [PATCH] smb: client: restore the data_offset bound in is_valid_oplock_break()

From: Paulo Alcantara

Date: Fri Aug 21 2026 - 13:07:22 EST


Bryam Vargas via B4 Relay <devnull+hexlabsecurity.proton.me@xxxxxxxxxx>
writes:

> From: Bryam Vargas <hexlabsecurity@xxxxxxxxx>
>
> Commit 83bfbd0bb902 ("cifs: Remove the RFC1002 header from smb_hdr")
> changed the quantity this bound is measured against. It used to be
> srv->total_read minus the 4-byte RFC1002 preamble that total_read then
> included, so it was the SMB message length. The same commit stopped
> counting the preamble, and the mechanical substitution to
> srv->total_read - srv->pdu_size left an expression that is identically
> zero: standard_receive3() reads MID_HEADER_SIZE() bytes and then exactly
> pdu_length - MID_HEADER_SIZE() more, adding both to total_read.
>
> len is therefore 0, the subtraction below it wraps, and no __u32
> DataOffset can exceed the result, so the check from commit 097f5863b1a0
> ("cifs: read overflow in is_valid_oplock_break()") no longer rejects
> anything. Use total_read, which is now the message length on its own.
> ...

Applied.