mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-08-29 09:15:39 -04:00
cifs: validate idmap key payload length
The cifs.idmap key type stores its payload length in key->datalen, which is limited to U16_MAX. Accepting a larger key payload truncates the recorded length and can make later users interpret the payload using inconsistent bounds. Reject oversized preparsed payloads before allocating or copying them. This keeps key->datalen consistent with the stored data for both inline and separately allocated idmap payloads. Signed-off-by: Li Qiang <liqiang01@kylinos.cn> Signed-off-by: Steve French <stfrench@microsoft.com>
This commit is contained in:
@@ -68,6 +68,9 @@ cifs_idmap_key_instantiate(struct key *key, struct key_preparsed_payload *prep)
|
||||
{
|
||||
char *payload;
|
||||
|
||||
if (prep->datalen > U16_MAX)
|
||||
return -EINVAL;
|
||||
|
||||
/*
|
||||
* If the payload is less than or equal to the size of a pointer, then
|
||||
* an allocation here is wasteful. Just copy the data directly to the
|
||||
|
||||
Reference in New Issue
Block a user