mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Sasha Levin <sashal@kernel.org>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: Namjae Jeon <linkinjeon@kernel.org>,
	zdi-disclosures@trendmicro.com,
	Steve French <stfrench@microsoft.com>,
	Sasha Levin <sashal@kernel.org>,
	sfrench@samba.org, linux-cifs@vger.kernel.org
Subject: [PATCH AUTOSEL 6.4 12/54] ksmbd: validate session id and tree id in compound request
Date: Sun, 13 Aug 2023 11:48:51 -0400	[thread overview]
Message-ID: <20230813154934.1067569-12-sashal@kernel.org> (raw)
In-Reply-To: <20230813154934.1067569-1-sashal@kernel.org>

From: Namjae Jeon <linkinjeon@kernel.org>

[ Upstream commit 3df0411e132ee74a87aa13142dfd2b190275332e ]

`smb2_get_msg()` in smb2_get_ksmbd_tcon() and smb2_check_user_session()
will always return the first request smb2 header in a compound request.
if `SMB2_TREE_CONNECT_HE` is the first command in compound request, will
return 0, i.e. The tree id check is skipped.
This patch use ksmbd_req_buf_next() to get current command in compound.

Reported-by: zdi-disclosures@trendmicro.com # ZDI-CAN-21506
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/smb/server/smb2pdu.c | 12 ++++++------
 1 file changed, 6 insertions(+), 6 deletions(-)

diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c
index bd3da6cc6a98e..f4421d4bff0f8 100644
--- a/fs/smb/server/smb2pdu.c
+++ b/fs/smb/server/smb2pdu.c
@@ -87,9 +87,9 @@ struct channel *lookup_chann_list(struct ksmbd_session *sess, struct ksmbd_conn
  */
 int smb2_get_ksmbd_tcon(struct ksmbd_work *work)
 {
-	struct smb2_hdr *req_hdr = smb2_get_msg(work->request_buf);
+	struct smb2_hdr *req_hdr = ksmbd_req_buf_next(work);
 	unsigned int cmd = le16_to_cpu(req_hdr->Command);
-	int tree_id;
+	unsigned int tree_id;
 
 	if (cmd == SMB2_TREE_CONNECT_HE ||
 	    cmd ==  SMB2_CANCEL_HE ||
@@ -114,7 +114,7 @@ int smb2_get_ksmbd_tcon(struct ksmbd_work *work)
 			pr_err("The first operation in the compound does not have tcon\n");
 			return -EINVAL;
 		}
-		if (work->tcon->id != tree_id) {
+		if (tree_id != UINT_MAX && work->tcon->id != tree_id) {
 			pr_err("tree id(%u) is different with id(%u) in first operation\n",
 					tree_id, work->tcon->id);
 			return -EINVAL;
@@ -559,9 +559,9 @@ int smb2_allocate_rsp_buf(struct ksmbd_work *work)
  */
 int smb2_check_user_session(struct ksmbd_work *work)
 {
-	struct smb2_hdr *req_hdr = smb2_get_msg(work->request_buf);
+	struct smb2_hdr *req_hdr = ksmbd_req_buf_next(work);
 	struct ksmbd_conn *conn = work->conn;
-	unsigned int cmd = conn->ops->get_cmd_val(work);
+	unsigned int cmd = le16_to_cpu(req_hdr->Command);
 	unsigned long long sess_id;
 
 	/*
@@ -587,7 +587,7 @@ int smb2_check_user_session(struct ksmbd_work *work)
 			pr_err("The first operation in the compound does not have sess\n");
 			return -EINVAL;
 		}
-		if (work->sess->id != sess_id) {
+		if (sess_id != ULLONG_MAX && work->sess->id != sess_id) {
 			pr_err("session id(%llu) is different with the first operation(%lld)\n",
 					sess_id, work->sess->id);
 			return -EINVAL;
-- 
2.40.1


  parent reply	other threads:[~2023-08-13 15:50 UTC|newest]

Thread overview: 59+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2023-08-13 15:48 [PATCH AUTOSEL 6.4 01/54] ksmbd: Fix unsigned expression compared with zero Sasha Levin
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 02/54] phy: qcom-snps-femto-v2: keep cfg_ahb_clk enabled during runtime suspend Sasha Levin
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 03/54] phy: qcom-snps-femto-v2: use qcom_snps_hsphy_suspend/resume error code Sasha Levin
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 04/54] media: amphion: use dev_err_probe Sasha Levin
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 05/54] media: imx-jpeg: Support to assign slot for encoder/decoder Sasha Levin
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 06/54] media: pulse8-cec: handle possible ping error Sasha Levin
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 07/54] media: pci: cx23885: fix error handling for cx23885 ATSC boards Sasha Levin
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 08/54] platform/x86: serial-multi-instantiate: Auto detect IRQ resource for CSC3551 Sasha Levin
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 09/54] 9p: virtio: fix unlikely null pointer deref in handle_rerror Sasha Levin
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 10/54] 9p: virtio: make sure 'offs' is initialized in zc_request Sasha Levin
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 11/54] ksmbd: fix out of bounds in smb3_decrypt_req() Sasha Levin
2023-08-13 15:48 ` Sasha Levin [this message]
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 13/54] ksmbd: no response from compound read Sasha Levin
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 14/54] ksmbd: fix out of bounds in init_smb2_rsp_hdr() Sasha Levin
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 15/54] ASoC: da7219: Flush pending AAD IRQ when suspending Sasha Levin
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 16/54] ASoC: da7219: Check for failure reading AAD IRQ events Sasha Levin
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 17/54] ASoC: nau8821: Add DMI quirk mechanism for active-high jack-detect Sasha Levin
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 18/54] thermal: core: constify params in thermal_zone_device_register Sasha Levin
2023-08-22 10:43   ` Pavel Machek
2023-08-22 11:31     ` Greg KH
2023-09-05  6:03       ` Ahmad Fatoum
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 19/54] net: hns3: add tm flush when setting tm Sasha Levin
2023-08-13 15:48 ` [PATCH AUTOSEL 6.4 20/54] ethernet: atheros: fix return value check in atl1c_tso_csum() Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 21/54] vxlan: generalize vxlan_parse_gpe_hdr and remove unused args Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 22/54] m68k: Fix invalid .section syntax Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 23/54] btrfs: remove BUG_ON()'s in add_new_free_space() Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 24/54] s390/dasd: use correct number of retries for ERP requests Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 25/54] s390/dasd: fix hanging device after request requeue Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 26/54] fs/nls: make load_nls() take a const parameter Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 27/54] cifs: fix charset issue in reconnection Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 28/54] ASoC: rt5682-sdw: fix for JD event handling in ClockStop Mode0 Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 29/54] ASoc: codecs: ES8316: Fix DMIC config Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 30/54] ASoC: rt712-sdca: fix for JD event handling in ClockStop Mode0 Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 31/54] ASoC: rt711: " Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 32/54] ASoC: rt711-sdca: " Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 33/54] ASoC: atmel: Fix the 8K sample parameter in I2SC master Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 34/54] ALSA: usb-audio: Add quirk for Microsoft Modern Wireless Headset Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 35/54] platform/x86/amd/pmf: reduce verbosity of apmf_get_system_params Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 36/54] platform/x86/amd/pmf: Notify OS power slider update Sasha Levin
2023-08-22 10:44   ` Pavel Machek
2023-08-22 14:46     ` Mario Limonciello
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 37/54] platform/x86: intel: hid: Always call BTNL ACPI method Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 38/54] platform/x86/intel/hid: Add HP Dragonfly G2 to VGBS DMI quirks Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 39/54] platform/x86: think-lmi: Use kfree_sensitive instead of kfree Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 40/54] platform/x86: asus-wmi: Fix setting RGB mode on some TUF laptops Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 41/54] platform/x86: huawei-wmi: Silence ambient light sensor Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 42/54] drm/amd/smu: use AverageGfxclkFrequency* to replace previous GFX Curr Clock Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 43/54] drm/amd/display: Guard DCN31 PHYD32CLK logic against chip family Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 44/54] drm/amd/display: Exit idle optimizations before attempt to access PHY Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 45/54] ovl: Always reevaluate the file signature for IMA Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 46/54] ata: pata_arasan_cf: Use dev_err_probe() instead dev_err() in data_xfer() Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 47/54] rbd: make get_lock_owner_info() return a single locker or NULL Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 48/54] rbd: harden get_lock_owner_info() a bit Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 49/54] ALSA: usb-audio: Update for native DSD support quirks Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 50/54] staging: fbtft: ili9341: use macro FBTFT_REGISTER_SPI_DRIVER Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 51/54] LoongArch: Only fiddle with CHECKFLAGS if `need-compiler' Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 52/54] LoongArch: Fix CMDLINE_EXTEND and CMDLINE_BOOTLOADER handling Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 53/54] security: keys: perform capable check only on privileged operations Sasha Levin
2023-08-13 15:49 ` [PATCH AUTOSEL 6.4 54/54] kprobes: Prohibit probing on CFI preamble symbol Sasha Levin

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20230813154934.1067569-12-sashal@kernel.org \
    --to=sashal@kernel.org \
    --cc=linkinjeon@kernel.org \
    --cc=linux-cifs@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=sfrench@samba.org \
    --cc=stable@vger.kernel.org \
    --cc=stfrench@microsoft.com \
    --cc=zdi-disclosures@trendmicro.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®