Re: [PATCH] ksmbd: fix heap out-of-bounds write in SMB2_CREATE context stacking
From: Namjae Jeon
Date: Thu Oct 08 2026 - 22:35:44 EST
On Fri, Oct 9, 2026 at 2:05 AM Henry Martin <bsdhenrymartin@xxxxxxxxx> wrote:
>
> smb2_open() appends up to six create contexts (lease, mxac, disk_id,
> durable, posix, aapl) back-to-back without checking the total length
> against work->response_sz. A non-compound SMB2_CREATE only gets the
> 448-byte small response buffer, which also carries the 4-byte rfc1002
> length word, leaving 292 bytes for contexts. The AAPL response alone
> occupies 128 fixed bytes, so a client stacking contexts (up to 416)
> overruns the kmalloc-512 object into the adjacent allocation with a
> deterministic zero-fill.
>
> Compute the worst-case context total from the per-dialect
> conn->vals->create_*_size table and grow the response buffer to fit
> before writing any context, so legitimate requests keep working
> unchanged.
>
> This vulnerability was discovered by Tencent CodeBuddy Security.
>
> Fixes: 8f1b796ff1135 ("ksmbd: add AAPL kAAPL_SERVER_QUERY create context support")
> Signed-off-by: Henry Martin <bsdhenrymartin@xxxxxxxxx>
Please check the following patch in #ksmbd-for-next branch.
https://git.kernel.org/pub/scm/linux/kernel/git/linkinjeon/smb.git/commit/?id=4ceeaa7b1a1a022ee329c4068339b3f44c1514a2
Thanks.