| From 0318b293e5496c5a848da18f5fa676d391c69e9c Mon Sep 17 00:00:00 2001 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Tue, 11 Mar 2025 17:22:05 +0300 |
| Subject: cifs: Fix integer overflow while processing actimeo mount option |
| |
| From: Murad Masimov <m.masimov@mt-integration.ru> |
| |
| [ Upstream commit 64f690ee22c99e16084e0e45181b2a1eed2fa149 ] |
| |
| User-provided mount parameter actimeo of type u32 is intended to have |
| an upper limit, but before it is validated, the value is converted from |
| seconds to jiffies which can lead to an integer overflow. |
| |
| Found by Linux Verification Center (linuxtesting.org) with SVACE. |
| |
| Fixes: 6d20e8406f09 ("cifs: add attribute cache timeout (actimeo) tunable") |
| Signed-off-by: Murad Masimov <m.masimov@mt-integration.ru> |
| Signed-off-by: Steve French <stfrench@microsoft.com> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| fs/cifs/fs_context.c | 2 +- |
| 1 file changed, 1 insertion(+), 1 deletion(-) |
| |
| diff --git a/fs/cifs/fs_context.c b/fs/cifs/fs_context.c |
| index 9b1c0e0dfc63b..f45a29a51700b 100644 |
| --- a/fs/cifs/fs_context.c |
| +++ b/fs/cifs/fs_context.c |
| @@ -1069,7 +1069,7 @@ static int smb3_fs_context_parse_param(struct fs_context *fc, |
| ctx->acdirmax = HZ * result.uint_32; |
| break; |
| case Opt_actimeo: |
| - if (HZ * result.uint_32 > CIFS_MAX_ACTIMEO) { |
| + if (result.uint_32 > CIFS_MAX_ACTIMEO / HZ) { |
| cifs_errorf(fc, "timeout too large\n"); |
| goto cifs_parse_mount_err; |
| } |
| -- |
| 2.39.5 |
| |