ksmbd: don't need 8byte alignment for request length in ksmbd_check_message
authorNamjae Jeon <linkinjeon@kernel.org>
Thu, 28 Oct 2021 23:09:50 +0000 (08:09 +0900)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Thu, 18 Nov 2021 18:17:15 +0000 (19:17 +0100)
commit b53ad8107ee873795ecb5039d46b5d5502d404f2 upstream.

When validating request length in ksmbd_check_message, 8byte alignment
is not needed for compound request. It can cause wrong validation
of request length.

Fixes: e2f34481b24d ("cifsd: add server-side procedures for SMB3")
Cc: stable@vger.kernel.org # v5.15
Acked-by: Hyunchul Lee <hyc.lee@gmail.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
fs/ksmbd/smb2misc.c

index 030ca57..9f516f7 100644 (file)
@@ -358,12 +358,10 @@ int ksmbd_smb2_check_message(struct ksmbd_work *work)
                hdr = &pdu->hdr;
        }
 
-       if (le32_to_cpu(hdr->NextCommand) > 0) {
+       if (le32_to_cpu(hdr->NextCommand) > 0)
                len = le32_to_cpu(hdr->NextCommand);
-       } else if (work->next_smb2_rcv_hdr_off) {
+       else if (work->next_smb2_rcv_hdr_off)
                len -= work->next_smb2_rcv_hdr_off;
-               len = round_up(len, 8);
-       }
 
        if (check_smb2_hdr(hdr))
                return 1;