diff options
author | Namjae Jeon <linkinjeon@kernel.org> | 2021-10-29 01:09:50 +0200 |
---|---|---|
committer | Steve French <stfrench@microsoft.com> | 2021-11-07 05:52:06 +0100 |
commit | b53ad8107ee873795ecb5039d46b5d5502d404f2 (patch) | |
tree | 9f27356e00aed8b59168074e6867d3bbd3ac197b /fs/ksmbd | |
parent | ksmbd: Fix buffer length check in fsctl_validate_negotiate_info() (diff) | |
download | linux-b53ad8107ee873795ecb5039d46b5d5502d404f2.tar.xz linux-b53ad8107ee873795ecb5039d46b5d5502d404f2.zip |
ksmbd: don't need 8byte alignment for request length in ksmbd_check_message
When validating request length in ksmbd_check_message, 8byte alignment
is not needed for compound request. It can cause wrong validation
of request length.
Fixes: e2f34481b24d ("cifsd: add server-side procedures for SMB3")
Cc: stable@vger.kernel.org # v5.15
Acked-by: Hyunchul Lee <hyc.lee@gmail.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
Diffstat (limited to 'fs/ksmbd')
-rw-r--r-- | fs/ksmbd/smb2misc.c | 6 |
1 files changed, 2 insertions, 4 deletions
diff --git a/fs/ksmbd/smb2misc.c b/fs/ksmbd/smb2misc.c index 2385622cc3c8..0239fa96926c 100644 --- a/fs/ksmbd/smb2misc.c +++ b/fs/ksmbd/smb2misc.c @@ -353,12 +353,10 @@ int ksmbd_smb2_check_message(struct ksmbd_work *work) __u32 clc_len; /* calculated length */ __u32 len = get_rfc1002_len(pdu); - if (le32_to_cpu(hdr->NextCommand) > 0) { + if (le32_to_cpu(hdr->NextCommand) > 0) len = le32_to_cpu(hdr->NextCommand); - } else if (work->next_smb2_rcv_hdr_off) { + else if (work->next_smb2_rcv_hdr_off) len -= work->next_smb2_rcv_hdr_off; - len = round_up(len, 8); - } if (check_smb2_hdr(hdr)) return 1; |