diff options
| author | Alon Shakevsky <shakevsky@berkeley.edu> | 2026-09-01 00:05:31 +0000 |
|---|---|---|
| committer | Namjae Jeon <linkinjeon@kernel.org> | 2026-09-02 17:58:15 +0900 |
| commit | 0480cee8cc3cc906124d398a9779eda144de6b41 (patch) | |
| tree | c6859c1ce69179b66985c1b3654944ccbfd188b4 /scripts/Makefile.thinlto | |
| parent | 0e753899627b5e28a9fea8bca98262a6f65a2452 (diff) | |
| download | linux-0480cee8cc3cc906124d398a9779eda144de6b41.tar.gz linux-0480cee8cc3cc906124d398a9779eda144de6b41.zip | |
ksmbd: validate COPYCHUNK source and target ranges
ksmbd_vfs_copy_file_ranges() rejects negative source offsets in the
copy loop, but it does not validate target offsets. It also calculates
lock and overlap endpoints before ensuring that either range fits within
MAX_LFS_FILESIZE.
When the target is an alternate data stream, the buffered path passes a
negative target offset to ksmbd_vfs_stream_write(). Let n be Length and
let -d be TargetOffset, where 0 < d < n <= XATTR_SIZE_MAX. For an empty
stream, the writer allocates n - d bytes, then copies n bytes starting d
bytes before the allocation. An authenticated SMB client can control d
and the source data, overwrite kernel heap memory, and crash the host.
Validate both ranges before lock, overlap, or I/O calculations.
Fixes: 8482150a0743 ("ksmbd: support copychunk for alternate data streams")
Assisted-by: Antiproof:GPT-5.6-Sol
Signed-off-by: Alon Shakevsky <shakevsky@berkeley.edu>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Diffstat (limited to 'scripts/Makefile.thinlto')
0 files changed, 0 insertions, 0 deletions
