Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1462251
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | [PATCH 3.2 84/94] cifs: dynamic allocation of ntlmssp blob |
| Date | 2016-08-14 20:10 +0200 |
| Message-ID | <s681d-31c-79@gated-at.bofh.it> (permalink) |
| References | <s5LnX-4sk-7@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
3.2.82-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: Jerome Marchand <jmarchan@redhat.com>
commit b8da344b74c822e966c6d19d6b2321efe82c5d97 upstream.
In sess_auth_rawntlmssp_authenticate(), the ntlmssp blob is allocated
statically and its size is an "empirical" 5*sizeof(struct
_AUTHENTICATE_MESSAGE) (320B on x86_64). I don't know where this value
comes from or if it was ever appropriate, but it is currently
insufficient: the user and domain name in UTF16 could take 1kB by
themselves. Because of that, build_ntlmssp_auth_blob() might corrupt
memory (out-of-bounds write). The size of ntlmssp_blob in
SMB2_sess_setup() is too small too (sizeof(struct _NEGOTIATE_MESSAGE)
+ 500).
This patch allocates the blob dynamically in
build_ntlmssp_auth_blob().
Signed-off-by: Jerome Marchand <jmarchan@redhat.com>
Signed-off-by: Steve French <smfrench@gmail.com>
[bwh: Backported to 3.2:
- Adjust context, indentation
- build_ntlmssp_auth_blob() is static
- Drop changes to smb2pdu.c
- Use cERROR() instead of cifs_dbg(VFS, ...)
- Use MAX_USERNAME_SIZE instead of CIFS_MAX_USERNAME_LEN]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
--- a/fs/cifs/sess.c
+++ b/fs/cifs/sess.c
@@ -444,19 +444,43 @@ static void build_ntlmssp_negotiate_blob
sec_blob->DomainName.MaximumLength = 0;
}
-/* We do not malloc the blob, it is passed in pbuffer, because its
- maximum possible size is fixed and small, making this approach cleaner.
- This function returns the length of the data in the blob */
-static int build_ntlmssp_auth_blob(unsigned char *pbuffer,
+static int size_of_ntlmssp_blob(struct cifs_ses *ses)
+{
+ int sz = sizeof(AUTHENTICATE_MESSAGE) + ses->auth_key.len
+ - CIFS_SESS_KEY_SIZE + CIFS_CPHTXT_SIZE + 2;
+
+ if (ses->domainName)
+ sz += 2 * strnlen(ses->domainName, CIFS_MAX_DOMAINNAME_LEN);
+ else
+ sz += 2;
+
+ if (ses->user_name)
+ sz += 2 * strnlen(ses->user_name, MAX_USERNAME_SIZE);
+ else
+ sz += 2;
+
+ return sz;
+}
+
+static int build_ntlmssp_auth_blob(unsigned char **pbuffer,
u16 *buflen,
struct cifs_ses *ses,
const struct nls_table *nls_cp)
{
int rc;
- AUTHENTICATE_MESSAGE *sec_blob = (AUTHENTICATE_MESSAGE *)pbuffer;
+ AUTHENTICATE_MESSAGE *sec_blob;
__u32 flags;
unsigned char *tmp;
+ rc = setup_ntlmv2_rsp(ses, nls_cp);
+ if (rc) {
+ cERROR(1, "Error %d during NTLMSSP authentication", rc);
+ *buflen = 0;
+ goto setup_ntlmv2_ret;
+ }
+ *pbuffer = kmalloc(size_of_ntlmssp_blob(ses), GFP_KERNEL);
+ sec_blob = (AUTHENTICATE_MESSAGE *)*pbuffer;
+
memcpy(sec_blob->Signature, NTLMSSP_SIGNATURE, 8);
sec_blob->MessageType = NtLmAuthenticate;
@@ -471,7 +495,7 @@ static int build_ntlmssp_auth_blob(unsig
flags |= NTLMSSP_NEGOTIATE_KEY_XCH;
}
- tmp = pbuffer + sizeof(AUTHENTICATE_MESSAGE);
+ tmp = *pbuffer + sizeof(AUTHENTICATE_MESSAGE);
sec_blob->NegotiateFlags = cpu_to_le32(flags);
sec_blob->LmChallengeResponse.BufferOffset =
@@ -479,13 +503,9 @@ static int build_ntlmssp_auth_blob(unsig
sec_blob->LmChallengeResponse.Length = 0;
sec_blob->LmChallengeResponse.MaximumLength = 0;
- sec_blob->NtChallengeResponse.BufferOffset = cpu_to_le32(tmp - pbuffer);
+ sec_blob->NtChallengeResponse.BufferOffset =
+ cpu_to_le32(tmp - *pbuffer);
if (ses->user_name != NULL) {
- rc = setup_ntlmv2_rsp(ses, nls_cp);
- if (rc) {
- cERROR(1, "Error %d during NTLMSSP authentication", rc);
- goto setup_ntlmv2_ret;
- }
memcpy(tmp, ses->auth_key.response + CIFS_SESS_KEY_SIZE,
ses->auth_key.len - CIFS_SESS_KEY_SIZE);
tmp += ses->auth_key.len - CIFS_SESS_KEY_SIZE;
@@ -503,7 +523,7 @@ static int build_ntlmssp_auth_blob(unsig
}
if (ses->domainName == NULL) {
- sec_blob->DomainName.BufferOffset = cpu_to_le32(tmp - pbuffer);
+ sec_blob->DomainName.BufferOffset = cpu_to_le32(tmp - *pbuffer);
sec_blob->DomainName.Length = 0;
sec_blob->DomainName.MaximumLength = 0;
tmp += 2;
@@ -512,14 +532,14 @@ static int build_ntlmssp_auth_blob(unsig
len = cifs_strtoUCS((__le16 *)tmp, ses->domainName,
MAX_USERNAME_SIZE, nls_cp);
len *= 2; /* unicode is 2 bytes each */
- sec_blob->DomainName.BufferOffset = cpu_to_le32(tmp - pbuffer);
+ sec_blob->DomainName.BufferOffset = cpu_to_le32(tmp - *pbuffer);
sec_blob->DomainName.Length = cpu_to_le16(len);
sec_blob->DomainName.MaximumLength = cpu_to_le16(len);
tmp += len;
}
if (ses->user_name == NULL) {
- sec_blob->UserName.BufferOffset = cpu_to_le32(tmp - pbuffer);
+ sec_blob->UserName.BufferOffset = cpu_to_le32(tmp - *pbuffer);
sec_blob->UserName.Length = 0;
sec_blob->UserName.MaximumLength = 0;
tmp += 2;
@@ -528,13 +548,13 @@ static int build_ntlmssp_auth_blob(unsig
len = cifs_strtoUCS((__le16 *)tmp, ses->user_name,
MAX_USERNAME_SIZE, nls_cp);
len *= 2; /* unicode is 2 bytes each */
- sec_blob->UserName.BufferOffset = cpu_to_le32(tmp - pbuffer);
+ sec_blob->UserName.BufferOffset = cpu_to_le32(tmp - *pbuffer);
sec_blob->UserName.Length = cpu_to_le16(len);
sec_blob->UserName.MaximumLength = cpu_to_le16(len);
tmp += len;
}
- sec_blob->WorkstationName.BufferOffset = cpu_to_le32(tmp - pbuffer);
+ sec_blob->WorkstationName.BufferOffset = cpu_to_le32(tmp - *pbuffer);
sec_blob->WorkstationName.Length = 0;
sec_blob->WorkstationName.MaximumLength = 0;
tmp += 2;
@@ -543,19 +563,19 @@ static int build_ntlmssp_auth_blob(unsig
(ses->ntlmssp->server_flags & NTLMSSP_NEGOTIATE_EXTENDED_SEC))
&& !calc_seckey(ses)) {
memcpy(tmp, ses->ntlmssp->ciphertext, CIFS_CPHTXT_SIZE);
- sec_blob->SessionKey.BufferOffset = cpu_to_le32(tmp - pbuffer);
+ sec_blob->SessionKey.BufferOffset = cpu_to_le32(tmp - *pbuffer);
sec_blob->SessionKey.Length = cpu_to_le16(CIFS_CPHTXT_SIZE);
sec_blob->SessionKey.MaximumLength =
cpu_to_le16(CIFS_CPHTXT_SIZE);
tmp += CIFS_CPHTXT_SIZE;
} else {
- sec_blob->SessionKey.BufferOffset = cpu_to_le32(tmp - pbuffer);
+ sec_blob->SessionKey.BufferOffset = cpu_to_le32(tmp - *pbuffer);
sec_blob->SessionKey.Length = 0;
sec_blob->SessionKey.MaximumLength = 0;
}
+ *buflen = tmp - *pbuffer;
setup_ntlmv2_ret:
- *buflen = tmp - pbuffer;
return rc;
}
@@ -578,7 +598,7 @@ CIFS_SessSetup(unsigned int xid, struct
struct key *spnego_key = NULL;
__le32 phase = NtLmNegotiate; /* NTLMSSP, if needed, is multistage */
u16 blob_len;
- char *ntlmsspblob = NULL;
+ unsigned char *ntlmsspblob = NULL;
if (ses == NULL)
return -EINVAL;
@@ -832,21 +852,7 @@ ssetup_ntlmssp_authenticate:
cpu_to_le16(sizeof(NEGOTIATE_MESSAGE));
break;
case NtLmAuthenticate:
- /*
- * 5 is an empirical value, large enough to hold
- * authenticate message plus max 10 of av paris,
- * domain, user, workstation names, flags, etc.
- */
- ntlmsspblob = kzalloc(
- 5*sizeof(struct _AUTHENTICATE_MESSAGE),
- GFP_KERNEL);
- if (!ntlmsspblob) {
- cERROR(1, "Can't allocate NTLMSSP blob");
- rc = -ENOMEM;
- goto ssetup_exit;
- }
-
- rc = build_ntlmssp_auth_blob(ntlmsspblob,
+ rc = build_ntlmssp_auth_blob(&ntlmsspblob,
&blob_len, ses, nls_cp);
if (rc)
goto ssetup_exit;
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[PATCH 3.2 00/94] 3.2.82-rc1 review Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 13:50 +0200 [PATCH 3.2 26/94] fs/cifs: correctly to anonymous authentication for the LANMAN authentication Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 13:50 +0200 [PATCH 3.2 23/94] x86/PCI: Mark Broadwell-EP Home Agent 1 as having non-compliant BARs Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 13:50 +0200 [PATCH 3.2 93/94] tcp: make challenge acks less predictable Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 13:50 +0200 [PATCH 3.2 62/94] UBIFS: Implement ->migratepage() Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:00 +0200 [PATCH 3.2 42/94] x86, build: copy ldlinux.c32 to image.iso Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:00 +0200 [PATCH 3.2 54/94] kvm: Fix irq route entries exceeding KVM_MAX_IRQ_ROUTES Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:00 +0200 [PATCH 3.2 13/94] USB: serial: option: add even more ZTE device ids Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:00 +0200 [PATCH 3.2 35/94] Input: xpad - prevent spurious input from wired Xbox 360 controllers Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:00 +0200 [PATCH 3.2 43/94] fix d_walk()/non-delayed __d_free() race Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:00 +0200 [PATCH 3.2 18/94] powerpc/mm/hash64: Factor out hash preload psize check Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:00 +0200 [PATCH 3.2 86/94] proc: prevent stacking filesystems on top Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:10 +0200 [PATCH 3.2 34/94] RDMA/cxgb3: device driver frees DMA memory with different size Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:10 +0200 [PATCH 3.2 22/94] net/mlx4_core: Fix access to uninitialized index Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:10 +0200 [PATCH 3.2 82/94] xenbus: don't BUG() on user mode induced condition Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:10 +0200 [PATCH 3.2 69/94] ALSA: dummy: Fix a use-after-free at closing Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:10 +0200 [PATCH 3.2 74/94] NFS: Fix another OPEN_DOWNGRADE bug Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:10 +0200 [PATCH 3.2 73/94] ALSA: echoaudio: Fix memory allocation Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:10 +0200 [PATCH 3.2 61/94] mm: Export migrate_page_move_mapping and migrate_page_copy Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:10 +0200 [PATCH 3.2 02/94] ath5k: Change led pin configuration for compaq c700 laptop Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:10 +0200 Re: [PATCH 3.2 00/94] 3.2.82-rc1 review Guenter Roeck <linux@roeck-us.net> - 2016-08-14 17:10 +0200 [PATCH 3.2 39/94] ARM: fix PTRACE_SETVFPREGS on SMP systems Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:00 +0200 [PATCH 3.2 85/94] fs: limit filesystem stacking depth Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:00 +0200 [PATCH 3.2 11/94] tty: vt, return error when con_startup fails Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:00 +0200 [PATCH 3.2 91/94] tipc: fix an infoleak in tipc_nl_compat_link_dump Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:00 +0200 [PATCH 3.2 15/94] MIPS: Adjust set_pte() SMP fix to handle R10000_LLSC_WAR Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:00 +0200 [PATCH 3.2 60/94] ubi: Make recover_peb power cut aware Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:00 +0200 [PATCH 3.2 03/94] crypto: s5p-sss - Fix missed interrupts when working with 8 kB blocks Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:00 +0200 [PATCH 3.2 64/94] xen/pciback: Fix conf_space read/write overlap check. Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:00 +0200 [PATCH 3.2 25/94] fs/cifs: correctly to anonymous authentication via NTLMSSP Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:00 +0200 [PATCH 3.2 37/94] Input: pwm-beeper - fix - scheduling while atomic Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200 [PATCH 3.2 21/94] mmc: mmc: Fix partition switch timeout for some eMMCs Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200 [PATCH 3.2 88/94] ALSA: timer: Fix leak in SNDRV_TIMER_IOCTL_PARAMS Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200 [PATCH 3.2 01/94] regmap: cache: Fix typo in cache_bypass parameter description Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200 [PATCH 3.2 63/94] can: fix oops caused by wrong rtnl dellink usage Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200 [PATCH 3.2 77/94] x86/amd_nb: Fix boot crash on non-AMD systems Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200 [PATCH 3.2 79/94] bonding: prevent out of bound accesses Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200 [PATCH 3.2 06/94] crypto: s5p-sss - fix incorrect usage of scatterlists api Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200 [PATCH 3.2 59/94] can: at91_can: RX queue could get stuck at high bus load Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200 [PATCH 3.2 70/94] fs/nilfs2: fix potential underflow in call to crc32_le Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200 [PATCH 3.2 71/94] staging: iio: accel: fix error check Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200 [PATCH 3.2 84/94] cifs: dynamic allocation of ntlmssp blob Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200 [PATCH 3.2 52/94] kernel/sysrq, watchdog, sched/core: Reset watchdog on all CPUs while processing sysrq-w Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200 [PATCH 3.2 40/94] KVM: x86: fix OOPS after invalid KVM_SET_DEBUGREGS Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200 [PATCH 3.2 53/94] base: make module_create_drivers_dir race-free Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200 [PATCH 3.2 87/94] USB: usbfs: fix potential infoleak in devio Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:20 +0200 [PATCH 3.2 48/94] staging:iio: trigger fixes for repeat request of same trigger and allocation failure Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:20 +0200 [PATCH 3.2 09/94] ext4: fix hang when processing corrupted orphaned inode list Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:20 +0200 [PATCH 3.2 75/94] batman-adv: Fix use-after-free/double-free of tt_req_node Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:20 +0200
csiph-web