| From a9cfbd642e7583c0e01d6b6917ec55816747c080 Mon Sep 17 00:00:00 2001 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Mon, 30 Mar 2026 13:11:27 -0700 |
| Subject: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath |
| |
| From: Fredric Cover <FredTheDude@proton.me> |
| |
| [ Upstream commit 78ec5bf2f589ec7fd8f169394bfeca541b077317 ] |
| |
| When cifs_sanitize_prepath is called with an empty string or a string |
| containing only delimiters (e.g., "/"), the current logic attempts to |
| check *(cursor2 - 1) before cursor2 has advanced. This results in an |
| out-of-bounds read. |
| |
| This patch adds an early exit check after stripping prepended |
| delimiters. If no path content remains, the function returns NULL. |
| |
| The bug was identified via manual audit and verified using a |
| standalone test case compiled with AddressSanitizer, which |
| triggered a SEGV on affected inputs. |
| |
| Signed-off-by: Fredric Cover <FredTheDude@proton.me> |
| Reviewed-by: Henrique Carvalho <[2]henrique.carvalho@suse.com> |
| Signed-off-by: Steve French <stfrench@microsoft.com> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| fs/smb/client/fs_context.c | 4 ++++ |
| 1 file changed, 4 insertions(+) |
| |
| diff --git a/fs/smb/client/fs_context.c b/fs/smb/client/fs_context.c |
| index 9000299e98cb4..35f2c94aafd14 100644 |
| --- a/fs/smb/client/fs_context.c |
| +++ b/fs/smb/client/fs_context.c |
| @@ -454,6 +454,10 @@ char *cifs_sanitize_prepath(char *prepath, gfp_t gfp) |
| while (IS_DELIM(*cursor1)) |
| cursor1++; |
| |
| + /* exit in case of only delimiters */ |
| + if (!*cursor1) |
| + return NULL; |
| + |
| /* copy the first letter */ |
| *cursor2 = *cursor1; |
| |
| -- |
| 2.53.0 |
| |