提交 38116603 编写于 作者: E Enzo Matsumiya 提交者: Yongqiang Liu

cifs: do not include page data when checking signature

stable inclusion
from stable-v4.19.271
commit 19f0577dd34b250e1595f8dd577d9c2b6c1dc85d
category: bugfix
bugzilla: https://gitee.com/openeuler/kernel/issues/I6DPF8
CVE: NA

Reference: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v4.19.271&id=19f0577dd34b250e1595f8dd577d9c2b6c1dc85d

--------------------------------

commit 30b2b219 upstream.

On async reads, page data is allocated before sending.  When the
response is received but it has no data to fill (e.g.
STATUS_END_OF_FILE), __calc_signature() will still include the pages in
its computation, leading to an invalid signature check.

This patch fixes this by not setting the async read smb_rqst page data
(zeroed by default) if its got_bytes is 0.

This can be reproduced/verified with xfstests generic/465.

Cc: <stable@vger.kernel.org>
Signed-off-by: NEnzo Matsumiya <ematsumiya@suse.de>
Reviewed-by: NPaulo Alcantara (SUSE) <pc@cjr.nz>
Signed-off-by: NSteve French <stfrench@microsoft.com>
Signed-off-by: NGreg Kroah-Hartman <gregkh@linuxfoundation.org>

Conflict:
  fs/cifs/smb2pdu.c
Signed-off-by: NLi Lingfeng <lilingfeng3@huawei.com>
Reviewed-by: NZhang Xiaoxu <zhangxiaoxu5@huawei.com>
Signed-off-by: NYongqiang Liu <liuyongqiang13@huawei.com>
上级 40124251
...@@ -3154,12 +3154,15 @@ smb2_readv_callback(struct mid_q_entry *mid) ...@@ -3154,12 +3154,15 @@ smb2_readv_callback(struct mid_q_entry *mid)
(struct smb2_sync_hdr *)rdata->iov[0].iov_base; (struct smb2_sync_hdr *)rdata->iov[0].iov_base;
unsigned int credits_received = 0; unsigned int credits_received = 0;
struct smb_rqst rqst = { .rq_iov = rdata->iov, struct smb_rqst rqst = { .rq_iov = rdata->iov,
.rq_nvec = 2, .rq_nvec = 2, };
.rq_pages = rdata->pages,
.rq_offset = rdata->page_offset, if (rdata->got_bytes) {
.rq_npages = rdata->nr_pages, rqst.rq_pages = rdata->pages;
.rq_pagesz = rdata->pagesz, rqst.rq_offset = rdata->page_offset;
.rq_tailsz = rdata->tailsz }; rqst.rq_npages = rdata->nr_pages;
rqst.rq_pagesz = rdata->pagesz;
rqst.rq_tailsz = rdata->tailsz;
}
cifs_dbg(FYI, "%s: mid=%llu state=%d result=%d bytes=%u\n", cifs_dbg(FYI, "%s: mid=%llu state=%d result=%d bytes=%u\n",
__func__, mid->mid, mid->mid_state, rdata->result, __func__, mid->mid, mid->mid_state, rdata->result,
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册