Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1462251

[PATCH 3.2 84/94] cifs: dynamic allocation of ntlmssp blob

From Ben Hutchings <ben@decadent.org.uk>
Newsgroups linux.kernel
Subject [PATCH 3.2 84/94] cifs: dynamic allocation of ntlmssp blob
Date 2016-08-14 20:10 +0200
Message-ID <s681d-31c-79@gated-at.bofh.it> (permalink)
References <s5LnX-4sk-7@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


3.2.82-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Jerome Marchand <jmarchan@redhat.com>

commit b8da344b74c822e966c6d19d6b2321efe82c5d97 upstream.

In sess_auth_rawntlmssp_authenticate(), the ntlmssp blob is allocated
statically and its size is an "empirical" 5*sizeof(struct
_AUTHENTICATE_MESSAGE) (320B on x86_64). I don't know where this value
comes from or if it was ever appropriate, but it is currently
insufficient: the user and domain name in UTF16 could take 1kB by
themselves. Because of that, build_ntlmssp_auth_blob() might corrupt
memory (out-of-bounds write). The size of ntlmssp_blob in
SMB2_sess_setup() is too small too (sizeof(struct _NEGOTIATE_MESSAGE)
+ 500).

This patch allocates the blob dynamically in
build_ntlmssp_auth_blob().

Signed-off-by: Jerome Marchand <jmarchan@redhat.com>
Signed-off-by: Steve French <smfrench@gmail.com>
[bwh: Backported to 3.2:
 - Adjust context, indentation
 - build_ntlmssp_auth_blob() is static
 - Drop changes to smb2pdu.c
 - Use cERROR() instead of cifs_dbg(VFS, ...)
 - Use MAX_USERNAME_SIZE instead of CIFS_MAX_USERNAME_LEN]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
--- a/fs/cifs/sess.c
+++ b/fs/cifs/sess.c
@@ -444,19 +444,43 @@ static void build_ntlmssp_negotiate_blob
 	sec_blob->DomainName.MaximumLength = 0;
 }
 
-/* We do not malloc the blob, it is passed in pbuffer, because its
-   maximum possible size is fixed and small, making this approach cleaner.
-   This function returns the length of the data in the blob */
-static int build_ntlmssp_auth_blob(unsigned char *pbuffer,
+static int size_of_ntlmssp_blob(struct cifs_ses *ses)
+{
+	int sz = sizeof(AUTHENTICATE_MESSAGE) + ses->auth_key.len
+		- CIFS_SESS_KEY_SIZE + CIFS_CPHTXT_SIZE + 2;
+
+	if (ses->domainName)
+		sz += 2 * strnlen(ses->domainName, CIFS_MAX_DOMAINNAME_LEN);
+	else
+		sz += 2;
+
+	if (ses->user_name)
+		sz += 2 * strnlen(ses->user_name, MAX_USERNAME_SIZE);
+	else
+		sz += 2;
+
+	return sz;
+}
+
+static int build_ntlmssp_auth_blob(unsigned char **pbuffer,
 					u16 *buflen,
 				   struct cifs_ses *ses,
 				   const struct nls_table *nls_cp)
 {
 	int rc;
-	AUTHENTICATE_MESSAGE *sec_blob = (AUTHENTICATE_MESSAGE *)pbuffer;
+	AUTHENTICATE_MESSAGE *sec_blob;
 	__u32 flags;
 	unsigned char *tmp;
 
+	rc = setup_ntlmv2_rsp(ses, nls_cp);
+	if (rc) {
+		cERROR(1, "Error %d during NTLMSSP authentication", rc);
+		*buflen = 0;
+		goto setup_ntlmv2_ret;
+	}
+	*pbuffer = kmalloc(size_of_ntlmssp_blob(ses), GFP_KERNEL);
+	sec_blob = (AUTHENTICATE_MESSAGE *)*pbuffer;
+
 	memcpy(sec_blob->Signature, NTLMSSP_SIGNATURE, 8);
 	sec_blob->MessageType = NtLmAuthenticate;
 
@@ -471,7 +495,7 @@ static int build_ntlmssp_auth_blob(unsig
 			flags |= NTLMSSP_NEGOTIATE_KEY_XCH;
 	}
 
-	tmp = pbuffer + sizeof(AUTHENTICATE_MESSAGE);
+	tmp = *pbuffer + sizeof(AUTHENTICATE_MESSAGE);
 	sec_blob->NegotiateFlags = cpu_to_le32(flags);
 
 	sec_blob->LmChallengeResponse.BufferOffset =
@@ -479,13 +503,9 @@ static int build_ntlmssp_auth_blob(unsig
 	sec_blob->LmChallengeResponse.Length = 0;
 	sec_blob->LmChallengeResponse.MaximumLength = 0;
 
-	sec_blob->NtChallengeResponse.BufferOffset = cpu_to_le32(tmp - pbuffer);
+	sec_blob->NtChallengeResponse.BufferOffset =
+				cpu_to_le32(tmp - *pbuffer);
 	if (ses->user_name != NULL) {
-		rc = setup_ntlmv2_rsp(ses, nls_cp);
-		if (rc) {
-			cERROR(1, "Error %d during NTLMSSP authentication", rc);
-			goto setup_ntlmv2_ret;
-		}
 		memcpy(tmp, ses->auth_key.response + CIFS_SESS_KEY_SIZE,
 				ses->auth_key.len - CIFS_SESS_KEY_SIZE);
 		tmp += ses->auth_key.len - CIFS_SESS_KEY_SIZE;
@@ -503,7 +523,7 @@ static int build_ntlmssp_auth_blob(unsig
 	}
 
 	if (ses->domainName == NULL) {
-		sec_blob->DomainName.BufferOffset = cpu_to_le32(tmp - pbuffer);
+		sec_blob->DomainName.BufferOffset = cpu_to_le32(tmp - *pbuffer);
 		sec_blob->DomainName.Length = 0;
 		sec_blob->DomainName.MaximumLength = 0;
 		tmp += 2;
@@ -512,14 +532,14 @@ static int build_ntlmssp_auth_blob(unsig
 		len = cifs_strtoUCS((__le16 *)tmp, ses->domainName,
 				    MAX_USERNAME_SIZE, nls_cp);
 		len *= 2; /* unicode is 2 bytes each */
-		sec_blob->DomainName.BufferOffset = cpu_to_le32(tmp - pbuffer);
+		sec_blob->DomainName.BufferOffset = cpu_to_le32(tmp - *pbuffer);
 		sec_blob->DomainName.Length = cpu_to_le16(len);
 		sec_blob->DomainName.MaximumLength = cpu_to_le16(len);
 		tmp += len;
 	}
 
 	if (ses->user_name == NULL) {
-		sec_blob->UserName.BufferOffset = cpu_to_le32(tmp - pbuffer);
+		sec_blob->UserName.BufferOffset = cpu_to_le32(tmp - *pbuffer);
 		sec_blob->UserName.Length = 0;
 		sec_blob->UserName.MaximumLength = 0;
 		tmp += 2;
@@ -528,13 +548,13 @@ static int build_ntlmssp_auth_blob(unsig
 		len = cifs_strtoUCS((__le16 *)tmp, ses->user_name,
 				    MAX_USERNAME_SIZE, nls_cp);
 		len *= 2; /* unicode is 2 bytes each */
-		sec_blob->UserName.BufferOffset = cpu_to_le32(tmp - pbuffer);
+		sec_blob->UserName.BufferOffset = cpu_to_le32(tmp - *pbuffer);
 		sec_blob->UserName.Length = cpu_to_le16(len);
 		sec_blob->UserName.MaximumLength = cpu_to_le16(len);
 		tmp += len;
 	}
 
-	sec_blob->WorkstationName.BufferOffset = cpu_to_le32(tmp - pbuffer);
+	sec_blob->WorkstationName.BufferOffset = cpu_to_le32(tmp - *pbuffer);
 	sec_blob->WorkstationName.Length = 0;
 	sec_blob->WorkstationName.MaximumLength = 0;
 	tmp += 2;
@@ -543,19 +563,19 @@ static int build_ntlmssp_auth_blob(unsig
 		(ses->ntlmssp->server_flags & NTLMSSP_NEGOTIATE_EXTENDED_SEC))
 			&& !calc_seckey(ses)) {
 		memcpy(tmp, ses->ntlmssp->ciphertext, CIFS_CPHTXT_SIZE);
-		sec_blob->SessionKey.BufferOffset = cpu_to_le32(tmp - pbuffer);
+		sec_blob->SessionKey.BufferOffset = cpu_to_le32(tmp - *pbuffer);
 		sec_blob->SessionKey.Length = cpu_to_le16(CIFS_CPHTXT_SIZE);
 		sec_blob->SessionKey.MaximumLength =
 				cpu_to_le16(CIFS_CPHTXT_SIZE);
 		tmp += CIFS_CPHTXT_SIZE;
 	} else {
-		sec_blob->SessionKey.BufferOffset = cpu_to_le32(tmp - pbuffer);
+		sec_blob->SessionKey.BufferOffset = cpu_to_le32(tmp - *pbuffer);
 		sec_blob->SessionKey.Length = 0;
 		sec_blob->SessionKey.MaximumLength = 0;
 	}
 
+	*buflen = tmp - *pbuffer;
 setup_ntlmv2_ret:
-	*buflen = tmp - pbuffer;
 	return rc;
 }
 
@@ -578,7 +598,7 @@ CIFS_SessSetup(unsigned int xid, struct
 	struct key *spnego_key = NULL;
 	__le32 phase = NtLmNegotiate; /* NTLMSSP, if needed, is multistage */
 	u16 blob_len;
-	char *ntlmsspblob = NULL;
+	unsigned char *ntlmsspblob = NULL;
 
 	if (ses == NULL)
 		return -EINVAL;
@@ -832,21 +852,7 @@ ssetup_ntlmssp_authenticate:
 				cpu_to_le16(sizeof(NEGOTIATE_MESSAGE));
 			break;
 		case NtLmAuthenticate:
-			/*
-			 * 5 is an empirical value, large enough to hold
-			 * authenticate message plus max 10 of av paris,
-			 * domain, user, workstation names, flags, etc.
-			 */
-			ntlmsspblob = kzalloc(
-				5*sizeof(struct _AUTHENTICATE_MESSAGE),
-				GFP_KERNEL);
-			if (!ntlmsspblob) {
-				cERROR(1, "Can't allocate NTLMSSP blob");
-				rc = -ENOMEM;
-				goto ssetup_exit;
-			}
-
-			rc = build_ntlmssp_auth_blob(ntlmsspblob,
+			rc = build_ntlmssp_auth_blob(&ntlmsspblob,
 						&blob_len, ses, nls_cp);
 			if (rc)
 				goto ssetup_exit;

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH 3.2 00/94] 3.2.82-rc1 review Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 13:50 +0200
  [PATCH 3.2 26/94] fs/cifs: correctly to anonymous authentication  for the LANMAN authentication Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 13:50 +0200
  [PATCH 3.2 23/94] x86/PCI: Mark Broadwell-EP Home Agent 1 as  having non-compliant BARs Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 13:50 +0200
  [PATCH 3.2 93/94] tcp: make challenge acks less predictable Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 13:50 +0200
  [PATCH 3.2 62/94] UBIFS: Implement ->migratepage() Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:00 +0200
  [PATCH 3.2 42/94] x86, build: copy ldlinux.c32 to image.iso Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:00 +0200
  [PATCH 3.2 54/94] kvm: Fix irq route entries exceeding  KVM_MAX_IRQ_ROUTES Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:00 +0200
  [PATCH 3.2 13/94] USB: serial: option: add even more ZTE device ids Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:00 +0200
  [PATCH 3.2 35/94] Input: xpad - prevent spurious input from wired  Xbox 360 controllers Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:00 +0200
  [PATCH 3.2 43/94] fix d_walk()/non-delayed __d_free() race Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:00 +0200
  [PATCH 3.2 18/94] powerpc/mm/hash64: Factor out hash preload  psize check Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:00 +0200
  [PATCH 3.2 86/94] proc: prevent stacking filesystems on top Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:10 +0200
  [PATCH 3.2 34/94] RDMA/cxgb3: device driver frees DMA memory with  different size Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:10 +0200
  [PATCH 3.2 22/94] net/mlx4_core: Fix access to uninitialized index Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:10 +0200
  [PATCH 3.2 82/94] xenbus: don't BUG() on user mode induced condition Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:10 +0200
  [PATCH 3.2 69/94] ALSA: dummy: Fix a use-after-free at closing Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:10 +0200
  [PATCH 3.2 74/94] NFS: Fix another OPEN_DOWNGRADE bug Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:10 +0200
  [PATCH 3.2 73/94] ALSA: echoaudio: Fix memory allocation Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:10 +0200
  [PATCH 3.2 61/94] mm: Export migrate_page_move_mapping and  migrate_page_copy Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:10 +0200
  [PATCH 3.2 02/94] ath5k: Change led pin configuration for compaq  c700 laptop Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:10 +0200
  Re: [PATCH 3.2 00/94] 3.2.82-rc1 review Guenter Roeck <linux@roeck-us.net> - 2016-08-14 17:10 +0200
  [PATCH 3.2 39/94] ARM: fix PTRACE_SETVFPREGS on SMP systems Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:00 +0200
  [PATCH 3.2 85/94] fs: limit filesystem stacking depth Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:00 +0200
  [PATCH 3.2 11/94] tty: vt, return error when con_startup fails Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:00 +0200
  [PATCH 3.2 91/94] tipc: fix an infoleak in tipc_nl_compat_link_dump Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:00 +0200
  [PATCH 3.2 15/94] MIPS: Adjust set_pte() SMP fix to handle  R10000_LLSC_WAR Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:00 +0200
  [PATCH 3.2 60/94] ubi: Make recover_peb power cut aware Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:00 +0200
  [PATCH 3.2 03/94] crypto: s5p-sss - Fix missed interrupts when  working with 8 kB blocks Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:00 +0200
  [PATCH 3.2 64/94] xen/pciback: Fix conf_space read/write overlap  check. Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:00 +0200
  [PATCH 3.2 25/94] fs/cifs: correctly to anonymous authentication  via NTLMSSP Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:00 +0200
  [PATCH 3.2 37/94] Input: pwm-beeper - fix - scheduling while atomic Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200
  [PATCH 3.2 21/94] mmc: mmc: Fix partition switch timeout for some  eMMCs Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200
  [PATCH 3.2 88/94] ALSA: timer: Fix leak in SNDRV_TIMER_IOCTL_PARAMS Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200
  [PATCH 3.2 01/94] regmap: cache: Fix typo in cache_bypass  parameter description Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200
  [PATCH 3.2 63/94] can: fix oops caused by wrong rtnl dellink usage Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200
  [PATCH 3.2 77/94] x86/amd_nb: Fix boot crash on non-AMD systems Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200
  [PATCH 3.2 79/94] bonding: prevent out of bound accesses Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200
  [PATCH 3.2 06/94] crypto: s5p-sss - fix incorrect usage of  scatterlists api Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200
  [PATCH 3.2 59/94] can: at91_can: RX queue could get stuck at high  bus load Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200
  [PATCH 3.2 70/94] fs/nilfs2: fix potential underflow in call to  crc32_le Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200
  [PATCH 3.2 71/94] staging: iio: accel: fix error check Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200
  [PATCH 3.2 84/94] cifs: dynamic allocation of ntlmssp blob Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200
  [PATCH 3.2 52/94] kernel/sysrq, watchdog, sched/core: Reset  watchdog on all CPUs while processing sysrq-w Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200
  [PATCH 3.2 40/94] KVM: x86: fix OOPS after invalid KVM_SET_DEBUGREGS Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200
  [PATCH 3.2 53/94] base: make module_create_drivers_dir race-free Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200
  [PATCH 3.2 87/94] USB: usbfs: fix potential infoleak in devio Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:20 +0200
  [PATCH 3.2 48/94] staging:iio: trigger fixes for repeat request  of same trigger and allocation failure Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:20 +0200
  [PATCH 3.2 09/94] ext4: fix hang when processing corrupted  orphaned inode list Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:20 +0200
  [PATCH 3.2 75/94] batman-adv: Fix use-after-free/double-free of  tt_req_node Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:20 +0200

csiph-web