diff options
| author | Li Qiang <liqiang01@kylinos.cn> | 2026-07-19 00:22:27 +0800 |
|---|---|---|
| committer | Steve French <stfrench@microsoft.com> | 2026-07-26 17:40:20 -0500 |
| commit | 455488cd5054bcc59db40fa1cc2c004031a5b2a5 (patch) | |
| tree | 985747f56872501a3f863253f4f80ff47d0519f2 | |
| parent | aed0714255c80d143e9f6d4ae00ee14423204ad5 (diff) | |
cifs: validate idmap key payload length
The cifs.idmap key type stores its payload length in key->datalen, which
is limited to U16_MAX. Accepting a larger key payload truncates the
recorded length and can make later users interpret the payload using
inconsistent bounds.
Reject oversized preparsed payloads before allocating or copying them.
This keeps key->datalen consistent with the stored data for both inline
and separately allocated idmap payloads.
Signed-off-by: Li Qiang <liqiang01@kylinos.cn>
Signed-off-by: Steve French <stfrench@microsoft.com>
| -rw-r--r-- | fs/smb/client/cifsacl.c | 3 |
1 files changed, 3 insertions, 0 deletions
diff --git a/fs/smb/client/cifsacl.c b/fs/smb/client/cifsacl.c index 9424281a7674..12005f46307d 100644 --- a/fs/smb/client/cifsacl.c +++ b/fs/smb/client/cifsacl.c @@ -68,6 +68,9 @@ cifs_idmap_key_instantiate(struct key *key, struct key_preparsed_payload *prep) { char *payload; + if (prep->datalen > U16_MAX) + return -EINVAL; + /* * If the payload is less than or equal to the size of a pointer, then * an allocation here is wasteful. Just copy the data directly to the |
