+5
−2
Loading
SMB2_change_notify called smb2_validate_iov() but ignored the return code, then kmemdup()ed using server provided OutputBufferOffset/Length. Check the return of smb2_validate_iov() and bail out on error. Discovered with help from the ZeroPath security tooling. Signed-off-by:Joshua Rogers <linux@joshua.hu> Reviewed-by:
Paulo Alcantara (Red Hat) <pc@manguebit.org> Cc: stable@vger.kernel.org Fixes: e3e94634 ("smb3: improve SMB3 change notification support") Signed-off-by:
Steve French <stfrench@microsoft.com>