get:
Show a patch.

patch:
Update a patch.

put:
Update a patch.

GET /api/1.2/patches/2223424/?format=api
HTTP 200 OK
Allow: GET, PUT, PATCH, HEAD, OPTIONS
Content-Type: application/json
Vary: Accept

{
    "id": 2223424,
    "url": "http://patchwork.ozlabs.org/api/1.2/patches/2223424/?format=api",
    "web_url": "http://patchwork.ozlabs.org/project/linux-cifs-client/patch/20260415102424.65161-1-phx0fer@gmail.com/",
    "project": {
        "id": 12,
        "url": "http://patchwork.ozlabs.org/api/1.2/projects/12/?format=api",
        "name": "Linux CIFS Client",
        "link_name": "linux-cifs-client",
        "list_id": "linux-cifs.vger.kernel.org",
        "list_email": "linux-cifs@vger.kernel.org",
        "web_url": "",
        "scm_url": "",
        "webscm_url": "",
        "list_archive_url": "",
        "list_archive_url_format": "",
        "commit_url_format": ""
    },
    "msgid": "<20260415102424.65161-1-phx0fer@gmail.com>",
    "list_archive_url": null,
    "date": "2026-04-15T10:24:24",
    "name": "[v2] smb: client: fix integer underflow in receive_encrypted_read()",
    "commit_ref": null,
    "pull_url": null,
    "state": "new",
    "archived": false,
    "hash": "5b506763e3b784c7d65710b1875a335d9095cea3",
    "submitter": {
        "id": 93127,
        "url": "http://patchwork.ozlabs.org/api/1.2/people/93127/?format=api",
        "name": "Dudu Lu",
        "email": "phx0fer@gmail.com"
    },
    "delegate": null,
    "mbox": "http://patchwork.ozlabs.org/project/linux-cifs-client/patch/20260415102424.65161-1-phx0fer@gmail.com/mbox/",
    "series": [
        {
            "id": 499959,
            "url": "http://patchwork.ozlabs.org/api/1.2/series/499959/?format=api",
            "web_url": "http://patchwork.ozlabs.org/project/linux-cifs-client/list/?series=499959",
            "date": "2026-04-15T10:24:24",
            "name": "[v2] smb: client: fix integer underflow in receive_encrypted_read()",
            "version": 2,
            "mbox": "http://patchwork.ozlabs.org/series/499959/mbox/"
        }
    ],
    "comments": "http://patchwork.ozlabs.org/api/patches/2223424/comments/",
    "check": "pending",
    "checks": "http://patchwork.ozlabs.org/api/patches/2223424/checks/",
    "tags": {},
    "related": [],
    "headers": {
        "Return-Path": "\n <linux-cifs+bounces-10830-incoming=patchwork.ozlabs.org@vger.kernel.org>",
        "X-Original-To": [
            "incoming@patchwork.ozlabs.org",
            "linux-cifs@vger.kernel.org"
        ],
        "Delivered-To": "patchwork-incoming@legolas.ozlabs.org",
        "Authentication-Results": [
            "legolas.ozlabs.org;\n\tdkim=pass (2048-bit key;\n unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256\n header.s=20251104 header.b=CIsaO4x4;\n\tdkim-atps=neutral",
            "legolas.ozlabs.org;\n spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org\n (client-ip=2600:3c04:e001:36c::12fc:5321; helo=tor.lore.kernel.org;\n envelope-from=linux-cifs+bounces-10830-incoming=patchwork.ozlabs.org@vger.kernel.org;\n receiver=patchwork.ozlabs.org)",
            "smtp.subspace.kernel.org;\n\tdkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com\n header.b=\"CIsaO4x4\"",
            "smtp.subspace.kernel.org;\n arc=none smtp.client-ip=209.85.216.44",
            "smtp.subspace.kernel.org;\n dmarc=pass (p=none dis=none) header.from=gmail.com",
            "smtp.subspace.kernel.org;\n spf=pass smtp.mailfrom=gmail.com"
        ],
        "Received": [
            "from tor.lore.kernel.org (tor.lore.kernel.org\n [IPv6:2600:3c04:e001:36c::12fc:5321])\n\t(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)\n\t key-exchange x25519 server-signature ECDSA (secp384r1) server-digest SHA384)\n\t(No client certificate requested)\n\tby legolas.ozlabs.org (Postfix) with ESMTPS id 4fwcjV4K4xz1yHM\n\tfor <incoming@patchwork.ozlabs.org>; Wed, 15 Apr 2026 20:25:34 +1000 (AEST)",
            "from smtp.subspace.kernel.org (conduit.subspace.kernel.org\n [100.90.174.1])\n\tby tor.lore.kernel.org (Postfix) with ESMTP id 05B1230C2CBE\n\tfor <incoming@patchwork.ozlabs.org>; Wed, 15 Apr 2026 10:24:43 +0000 (UTC)",
            "from localhost.localdomain (localhost.localdomain [127.0.0.1])\n\tby smtp.subspace.kernel.org (Postfix) with ESMTP id 2DA2D346A08;\n\tWed, 15 Apr 2026 10:24:31 +0000 (UTC)",
            "from mail-pj1-f44.google.com (mail-pj1-f44.google.com\n [209.85.216.44])\n\t(using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits))\n\t(No client certificate requested)\n\tby smtp.subspace.kernel.org (Postfix) with ESMTPS id E06B9347FD0\n\tfor <linux-cifs@vger.kernel.org>; Wed, 15 Apr 2026 10:24:29 +0000 (UTC)",
            "by mail-pj1-f44.google.com with SMTP id\n 98e67ed59e1d1-35d9c7bf9a1so5859693a91.3\n        for <linux-cifs@vger.kernel.org>;\n Wed, 15 Apr 2026 03:24:29 -0700 (PDT)",
            "from localhost.localdomain (69-172-89-235.static.imsbiz.com.\n [69.172.89.235])\n        by smtp.gmail.com with ESMTPSA id\n 98e67ed59e1d1-35fd308cf98sm1589444a91.7.2026.04.15.03.24.27\n        (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256);\n        Wed, 15 Apr 2026 03:24:28 -0700 (PDT)"
        ],
        "ARC-Seal": "i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116;\n\tt=1776248671; cv=none;\n b=kmZjwraCap1NV9w9Ir8808i5BZXiJizoYoE1ixQHO6thlie3OKOgRh0pr5VpXGPZdW8bsvgG1JordTt2AXV/Uc4Ozpn9+2zMa8v6+gb5vbWxoSyONILuhD72JO+IpwEoaoGrWC6lV8ImqJoXb3FiZv1HWZdlCAsPD4z2GY8Xi1Q=",
        "ARC-Message-Signature": "i=1; a=rsa-sha256; d=subspace.kernel.org;\n\ts=arc-20240116; t=1776248671; c=relaxed/simple;\n\tbh=jH3b89mCokoUYUcVzMlEhhYbB68wNmb556Lzxqa10t4=;\n\th=From:To:Cc:Subject:Date:Message-Id:MIME-Version;\n b=u/vh6y8jh5UvYGtlZJaU0dn3TEWc8PSNHDFkaQ8REiin/aCHbjzDiJnwpckrQNCJttfcrPwCl4XiDhJLBJC3R3kFgSkPmSbto4tVWfxGAfKhvl2BX7qjuUtE4bP8v1oQ69IcvSvOyt4QT6tAZwjM0X+6xH/P/0c3Fr/jCyGMUro=",
        "ARC-Authentication-Results": "i=1; smtp.subspace.kernel.org;\n dmarc=pass (p=none dis=none) header.from=gmail.com;\n spf=pass smtp.mailfrom=gmail.com;\n dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com\n header.b=CIsaO4x4; arc=none smtp.client-ip=209.85.216.44",
        "DKIM-Signature": "v=1; a=rsa-sha256; c=relaxed/relaxed;\n        d=gmail.com; s=20251104; t=1776248669; x=1776853469;\n darn=vger.kernel.org;\n        h=content-transfer-encoding:mime-version:message-id:date:subject:cc\n         :to:from:from:to:cc:subject:date:message-id:reply-to;\n        bh=nTKvDguA58XG3+7VXpkLC36Tot2TubEN1Y93bDE5iL8=;\n        b=CIsaO4x4bh0QQuhGYU9WlgTz634bdEO+mbRmT761rs0+QJWVmTU+CKyuIWEQ0Yf76V\n         yUNtRqfIWzCpbjtLJQ87Hv9eEaA7JLmFSxT28VtNlXiErLRKCnVp4i6whFwLyy1sSjSl\n         2+nng1WbJiGC+8eUKKxu2CMcf1QY/6I3qIEzhHSkF+xGhjXKEzUDOf2j9PPE9lScFwN9\n         2s3DpXx+ZwcYF2+mt6lRFRQUX7i8/QokyChWHv/64VJjenvj4PM5ZPptxm6pmXkxYmb/\n         VgtwkNBRk+9ekQTEJYwCfSQ40sunPuQdvq3YNqu0hVPbPf8HZT0sh8UYmNOFLMmoWdMk\n         POyg==",
        "X-Google-DKIM-Signature": "v=1; a=rsa-sha256; c=relaxed/relaxed;\n        d=1e100.net; s=20251104; t=1776248669; x=1776853469;\n        h=content-transfer-encoding:mime-version:message-id:date:subject:cc\n         :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date\n         :message-id:reply-to;\n        bh=nTKvDguA58XG3+7VXpkLC36Tot2TubEN1Y93bDE5iL8=;\n        b=cl4/B8p0Oum/+T2I7IJgavePLF+fpXCer9h5qGqiYYmLQafMZZto3QUCsg5RYazfGx\n         BefwgZbPGc7ICG3Nz8cd9ICzqgL38LOEu3JGmTjh0hWMd+6O1fRCHXEeWb5oldtetJcG\n         vw5GQ7huUUjY6p3wcbljO9eGxq+UZgRqqG4bQ8AY7FGSnIZLLlqRaWWJKutzNpMW8K5F\n         ZAe6hTdTf1sCOphR8YDvpVcp+8Aqfi3lRgSp4ORd2jC7fWb5tn+GArBIMBZxNk9oTVF6\n         5HWTbe5ScgbtmPr5cXYbSoOHNEtzA9opLBmhFX9/F5WHOtXJnJr3ZKqTAhm+/daBcvbV\n         oNtw==",
        "X-Gm-Message-State": "AOJu0YwOiDf9iDQwJB7YFNGXwbA7GNmrpEZ85oEmuXwb1GdqqXOXIHDN\n\ts3DBYCCISOH7cJwh2Nlv2UdUXHbaHiOxb4RDD1QloG9GJQdhbjHmKpBOP+Xs3A==",
        "X-Gm-Gg": "AeBDieuddP4MVkbbKE2wZEIpECq7qvoN1mLUUgRTc8vy2uLfETaXw4b/tmoCRyiK5x4\n\tjD0u9hToPdQQNStufbGpO3/Ez37KF2tdmGVgt4Ynlxj0AilMS/WMhhJQsR7uQjl6xTsMdxBZeO1\n\thxKCQOWYTyTIEXq7yN3NhqrLKXH4OecI+evybDyANAc4Y0GULAWUWLiq4sKQ1skD3whn+wv0yEm\n\tZUcknGnKnIM/GjGnhGC/OkkARICZhj9O/4uGeCqcX8w4mDxqNtQ2nvguITJE2eKtXgInGsdZxCn\n\tMDs9xFavxxVNy7v4qVdGi6n0I0fixR2gD1nh3DwSZNVlKOW8ExqmGN2/P5Zs9Cmei0yyrAaKmJ2\n\tM28egcxRESlMyCtVyZ+E8EFCOyhRWdZAOWYZvK7Q09w46CuRrNOhpJ6lXRinZ8Cs1Wx7sXxFDB4\n\tdRTu65CG0R8sgNT/cLkDEHsKvRlEk+KcvThsf5QslffuREKESsO3ZeOeQjG1FvbXsh3b06c5O7Y\n\t/Veru6OqvbH/e0qjWY=",
        "X-Received": "by 2002:a17:90b:3e4e:b0:35f:b870:9c9f with SMTP id\n 98e67ed59e1d1-35fb870a006mr11349389a91.12.1776248669204;\n        Wed, 15 Apr 2026 03:24:29 -0700 (PDT)",
        "From": "Dudu Lu <phx0fer@gmail.com>",
        "To": "smfrench@gmail.com",
        "Cc": "linux-cifs@vger.kernel.org,\n\tDudu Lu <phx0fer@gmail.com>",
        "Subject": "[PATCH v2] smb: client: fix integer underflow in\n receive_encrypted_read()",
        "Date": "Wed, 15 Apr 2026 18:24:24 +0800",
        "Message-Id": "<20260415102424.65161-1-phx0fer@gmail.com>",
        "X-Mailer": "git-send-email 2.39.3 (Apple Git-145)",
        "Precedence": "bulk",
        "X-Mailing-List": "linux-cifs@vger.kernel.org",
        "List-Id": "<linux-cifs.vger.kernel.org>",
        "List-Subscribe": "<mailto:linux-cifs+subscribe@vger.kernel.org>",
        "List-Unsubscribe": "<mailto:linux-cifs+unsubscribe@vger.kernel.org>",
        "MIME-Version": "1.0",
        "Content-Transfer-Encoding": "8bit"
    },
    "content": "In receive_encrypted_read(), the length of data to read from the socket\nis computed as:\n\n  len = le32_to_cpu(tr_hdr->OriginalMessageSize) -\n        server->vals->read_rsp_size;\n\nOriginalMessageSize comes from the server's transform header and is\nuntrusted. If a malicious server sends a value smaller than\nread_rsp_size, the unsigned subtraction wraps to a very large value\n(~4GB). This value is then passed to netfs_alloc_folioq_buffer() and\ncifs_read_iter_from_socket(), causing either a massive allocation\nattempt that fails with -ENOMEM (DoS), or under extreme memory\npressure, potential heap corruption.\n\nFix by adding a check that OriginalMessageSize is at least\nread_rsp_size before the subtraction. On failure, jump to\ndiscard_data to drain the remaining PDU from the socket, preventing\ndesync of subsequent reads on the connection.\n\nSigned-off-by: Dudu Lu <phx0fer@gmail.com>\n---\n fs/smb/client/smb2ops.c | 8 ++++++++\n 1 file changed, 8 insertions(+)",
    "diff": "diff --git a/fs/smb/client/smb2ops.c b/fs/smb/client/smb2ops.c\nindex 509fcea28a42..a2105f4b54db 100644\n--- a/fs/smb/client/smb2ops.c\n+++ b/fs/smb/client/smb2ops.c\n@@ -4943,6 +4943,14 @@ receive_encrypted_read(struct TCP_Server_Info *server, struct mid_q_entry **mid,\n \t\tgoto free_dw;\n \tserver->total_read += rc;\n \n+\tif (le32_to_cpu(tr_hdr->OriginalMessageSize) <\n+\t    server->vals->read_rsp_size) {\n+\t\tcifs_server_dbg(VFS, \"OriginalMessageSize %u too small for read response (%zu)\\n\",\n+\t\t\tle32_to_cpu(tr_hdr->OriginalMessageSize),\n+\t\t\tserver->vals->read_rsp_size);\n+\t\trc = -EINVAL;\n+\t\tgoto discard_data;\n+\t}\n \tlen = le32_to_cpu(tr_hdr->OriginalMessageSize) -\n \t\tserver->vals->read_rsp_size;\n \tdw->len = len;\n",
    "prefixes": [
        "v2"
    ]
}