summaryrefslogtreecommitdiff
path: root/scripts/Makefile.thinlto
diff options
context:
space:
mode:
authorAlon Shakevsky <shakevsky@berkeley.edu>2026-09-01 00:05:31 +0000
committerNamjae Jeon <linkinjeon@kernel.org>2026-09-02 17:58:15 +0900
commit0480cee8cc3cc906124d398a9779eda144de6b41 (patch)
treec6859c1ce69179b66985c1b3654944ccbfd188b4 /scripts/Makefile.thinlto
parent0e753899627b5e28a9fea8bca98262a6f65a2452 (diff)
downloadlinux-0480cee8cc3cc906124d398a9779eda144de6b41.tar.gz
linux-0480cee8cc3cc906124d398a9779eda144de6b41.zip
ksmbd: validate COPYCHUNK source and target ranges
ksmbd_vfs_copy_file_ranges() rejects negative source offsets in the copy loop, but it does not validate target offsets. It also calculates lock and overlap endpoints before ensuring that either range fits within MAX_LFS_FILESIZE. When the target is an alternate data stream, the buffered path passes a negative target offset to ksmbd_vfs_stream_write(). Let n be Length and let -d be TargetOffset, where 0 < d < n <= XATTR_SIZE_MAX. For an empty stream, the writer allocates n - d bytes, then copies n bytes starting d bytes before the allocation. An authenticated SMB client can control d and the source data, overwrite kernel heap memory, and crash the host. Validate both ranges before lock, overlap, or I/O calculations. Fixes: 8482150a0743 ("ksmbd: support copychunk for alternate data streams") Assisted-by: Antiproof:GPT-5.6-Sol Signed-off-by: Alon Shakevsky <shakevsky@berkeley.edu> Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Diffstat (limited to 'scripts/Makefile.thinlto')
0 files changed, 0 insertions, 0 deletions