ksmbd: add low bound validation to FSCTL_SET_ZERO_DATA
authorNamjae Jeon <linkinjeon@kernel.org>
Sun, 5 Mar 2023 12:04:00 +0000 (21:04 +0900)
committerSteve French <stfrench@microsoft.com>
Wed, 22 Mar 2023 21:38:33 +0000 (16:38 -0500)
Smatch static checker warning:
 fs/ksmbd/smb2pdu.c:7759 smb2_ioctl()
 warn: no lower bound on 'off'

Fix unexpected result that could caused from negative off and bfz.

Fixes: b5e5f9dfc915 ("ksmbd: check invalid FileOffset and BeyondFinalZero in FSCTL_ZERO_DATA")
Reported-by: Dan Carpenter <error27@gmail.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Reviewed-by: Sergey Senozhatsky <senozhatsky@chromium.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
fs/ksmbd/smb2pdu.c

index bc64d36c4dcfd810d77c3674cfe2cafa57786aea..f09afbdde58add1a08af943397594651827650bf 100644 (file)
@@ -7755,7 +7755,7 @@ int smb2_ioctl(struct ksmbd_work *work)
 
                off = le64_to_cpu(zero_data->FileOffset);
                bfz = le64_to_cpu(zero_data->BeyondFinalZero);
-               if (off > bfz) {
+               if (off < 0 || bfz < 0 || off > bfz) {
                        ret = -EINVAL;
                        goto out;
                }