get:
Show a patch.

patch:
Update a patch.

put:
Update a patch.

GET /api/patches/2224127/?format=api
HTTP 200 OK
Allow: GET, PUT, PATCH, HEAD, OPTIONS
Content-Type: application/json
Vary: Accept

{
    "id": 2224127,
    "url": "http://patchwork.ozlabs.org/api/patches/2224127/?format=api",
    "web_url": "http://patchwork.ozlabs.org/project/linux-cifs-client/patch/20260416213716.3118443-1-michael.bommarito@gmail.com/",
    "project": {
        "id": 12,
        "url": "http://patchwork.ozlabs.org/api/projects/12/?format=api",
        "name": "Linux CIFS Client",
        "link_name": "linux-cifs-client",
        "list_id": "linux-cifs.vger.kernel.org",
        "list_email": "linux-cifs@vger.kernel.org",
        "web_url": "",
        "scm_url": "",
        "webscm_url": "",
        "list_archive_url": "",
        "list_archive_url_format": "",
        "commit_url_format": ""
    },
    "msgid": "<20260416213716.3118443-1-michael.bommarito@gmail.com>",
    "list_archive_url": null,
    "date": "2026-04-16T21:37:16",
    "name": "smb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path",
    "commit_ref": null,
    "pull_url": null,
    "state": "new",
    "archived": false,
    "hash": "afb2be23d6a15adb9e4efc0b9ab225f7f4c762eb",
    "submitter": {
        "id": 93078,
        "url": "http://patchwork.ozlabs.org/api/people/93078/?format=api",
        "name": "Michael Bommarito",
        "email": "michael.bommarito@gmail.com"
    },
    "delegate": null,
    "mbox": "http://patchwork.ozlabs.org/project/linux-cifs-client/patch/20260416213716.3118443-1-michael.bommarito@gmail.com/mbox/",
    "series": [
        {
            "id": 500208,
            "url": "http://patchwork.ozlabs.org/api/series/500208/?format=api",
            "web_url": "http://patchwork.ozlabs.org/project/linux-cifs-client/list/?series=500208",
            "date": "2026-04-16T21:37:16",
            "name": "smb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path",
            "version": 1,
            "mbox": "http://patchwork.ozlabs.org/series/500208/mbox/"
        }
    ],
    "comments": "http://patchwork.ozlabs.org/api/patches/2224127/comments/",
    "check": "pending",
    "checks": "http://patchwork.ozlabs.org/api/patches/2224127/checks/",
    "tags": {},
    "related": [],
    "headers": {
        "Return-Path": "\n <linux-cifs+bounces-10876-incoming=patchwork.ozlabs.org@vger.kernel.org>",
        "X-Original-To": [
            "incoming@patchwork.ozlabs.org",
            "linux-cifs@vger.kernel.org"
        ],
        "Delivered-To": "patchwork-incoming@legolas.ozlabs.org",
        "Authentication-Results": [
            "legolas.ozlabs.org;\n\tdkim=pass (2048-bit key;\n unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256\n header.s=20251104 header.b=DQ3WhE1F;\n\tdkim-atps=neutral",
            "legolas.ozlabs.org;\n spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org\n (client-ip=172.234.253.10; helo=sea.lore.kernel.org;\n envelope-from=linux-cifs+bounces-10876-incoming=patchwork.ozlabs.org@vger.kernel.org;\n receiver=patchwork.ozlabs.org)",
            "smtp.subspace.kernel.org;\n\tdkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com\n header.b=\"DQ3WhE1F\"",
            "smtp.subspace.kernel.org;\n arc=none smtp.client-ip=209.85.219.51",
            "smtp.subspace.kernel.org;\n dmarc=pass (p=none dis=none) header.from=gmail.com",
            "smtp.subspace.kernel.org;\n spf=pass smtp.mailfrom=gmail.com"
        ],
        "Received": [
            "from sea.lore.kernel.org (sea.lore.kernel.org [172.234.253.10])\n\t(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)\n\t key-exchange x25519)\n\t(No client certificate requested)\n\tby legolas.ozlabs.org (Postfix) with ESMTPS id 4fxWc97015z1yCv\n\tfor <incoming@patchwork.ozlabs.org>; Fri, 17 Apr 2026 07:39:05 +1000 (AEST)",
            "from smtp.subspace.kernel.org (conduit.subspace.kernel.org\n [100.90.174.1])\n\tby sea.lore.kernel.org (Postfix) with ESMTP id A04E7305374F\n\tfor <incoming@patchwork.ozlabs.org>; Thu, 16 Apr 2026 21:37:36 +0000 (UTC)",
            "from localhost.localdomain (localhost.localdomain [127.0.0.1])\n\tby smtp.subspace.kernel.org (Postfix) with ESMTP id 110C836DA02;\n\tThu, 16 Apr 2026 21:37:35 +0000 (UTC)",
            "from mail-qv1-f51.google.com (mail-qv1-f51.google.com\n [209.85.219.51])\n\t(using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits))\n\t(No client certificate requested)\n\tby smtp.subspace.kernel.org (Postfix) with ESMTPS id A543735BDB2\n\tfor <linux-cifs@vger.kernel.org>; Thu, 16 Apr 2026 21:37:33 +0000 (UTC)",
            "by mail-qv1-f51.google.com with SMTP id\n 6a1803df08f44-8aca6bd57cfso34506d6.0\n        for <linux-cifs@vger.kernel.org>;\n Thu, 16 Apr 2026 14:37:33 -0700 (PDT)",
            "from server0.tail6e7dd.ts.net (c-68-48-65-54.hsd1.mi.comcast.net.\n [68.48.65.54])\n        by smtp.gmail.com with ESMTPSA id\n 6a1803df08f44-8ae6cb9eb87sm44823896d6.32.2026.04.16.14.37.31\n        (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);\n        Thu, 16 Apr 2026 14:37:31 -0700 (PDT)"
        ],
        "ARC-Seal": "i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116;\n\tt=1776375455; cv=none;\n b=K6PafQyLjPgybn7h22lGw/HW3svqA63khAQEs9+vxO3UheZiexPIBnBhW6bON37XDiSfN94mcjX+PB6B588qMTWgFychcwoOAjKjd2ViyMbSAkWiMpsLTpHCDJYZ80iN0l96p9LE+Nq0vp59QHVvWmOY/wjKh3nIKwS3gf5JPBE=",
        "ARC-Message-Signature": "i=1; a=rsa-sha256; d=subspace.kernel.org;\n\ts=arc-20240116; t=1776375455; c=relaxed/simple;\n\tbh=SnJvrHty8riZtWpxkx6xz7jX8W81q+Yde+8ssBb8Yyw=;\n\th=From:To:Cc:Subject:Date:Message-ID:MIME-Version;\n b=C6O97oay0fxlJ2RERzyTXzYJAk7nPB74p01GbA8tmT1YsW/YzmgFvEihd7kKRyuAUP1WlE0tBKP/f4GcsHEghgRGgzR4k6m8AbcYnZdMuwaRwiRPQ+n5eAaKWbSmZkfLypliztZt+nJlbhiiajI2nX9t2lotRdwIz0Vt8MkHDjw=",
        "ARC-Authentication-Results": "i=1; smtp.subspace.kernel.org;\n dmarc=pass (p=none dis=none) header.from=gmail.com;\n spf=pass smtp.mailfrom=gmail.com;\n dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com\n header.b=DQ3WhE1F; arc=none smtp.client-ip=209.85.219.51",
        "DKIM-Signature": "v=1; a=rsa-sha256; c=relaxed/relaxed;\n        d=gmail.com; s=20251104; t=1776375452; x=1776980252;\n darn=vger.kernel.org;\n        h=content-transfer-encoding:mime-version:message-id:date:subject:cc\n         :to:from:from:to:cc:subject:date:message-id:reply-to;\n        bh=huo/l1LVhl1kS5YAYBF6Ffd0gihdNIPyirAcpm8PYyY=;\n        b=DQ3WhE1FW8oCZhNMiUEXPKyHXJC+mjC0AEBe8XBcCSi95GVWb/qzZHyiDArldp7uhZ\n         wELm4JJ7ZCOzzdXoRPlHB0a/HfyCxngleZtDS51R9nnOz3H5TM/nd+rvLsVvO9e4sG52\n         voXAgo33dMr1DfnorR3OV5350WJbWoz8qlGhL7LyU8MlVW6eKeN3o5WWdmjtCpLruJi4\n         no6EOfSGqu5rzh7j6NVA3GS8iFay5i3EskCJP7Fw5nJAgJoLpAqgnY2MRYvV1aSzNURU\n         5WyVKS5uoZpRk+eeD3VaTA4xOvRuzEVU7DAwijH9c8vxuhPJVZ88mJtBBJRKBtWBz5G+\n         78ZA==",
        "X-Google-DKIM-Signature": "v=1; a=rsa-sha256; c=relaxed/relaxed;\n        d=1e100.net; s=20251104; t=1776375452; x=1776980252;\n        h=content-transfer-encoding:mime-version:message-id:date:subject:cc\n         :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date\n         :message-id:reply-to;\n        bh=huo/l1LVhl1kS5YAYBF6Ffd0gihdNIPyirAcpm8PYyY=;\n        b=IU2xLs8nqiQgNORVMCcJWQ2WjMLIyLXhHPrQpvrJhHd7p/jfqkcYoU767/AO/UCeMC\n         jkDfgNqnmp7mKFopV0w13nIgZ+YgocBqEvfbnYxG5GEWMP1Kqp+j/9t8sfK4x0iBwL69\n         ObNzgr8DNnHKgXgVwRFFHc69iaAseDZQQXyPWnv9DnqQo+5ZA9gxwV4eJwlLbqN6MjxK\n         RY4fp943b+4iRnnogbhB82RoBoG9q95HBfST/qx0UMG8BH11PThZEU+Z118BhS93ml60\n         98VDQytqEoI658deiSGdVCJ7uAF6HjNLl8DA19wooCXIn+W1Jx4bQiRIFEwnoTw7sIn+\n         Q1qA==",
        "X-Forwarded-Encrypted": "i=1;\n AFNElJ/N9W+OWllkuVfLBvvtmYsUj103HUIbHHqRCv1Ef0SaVXneZmO8FE8o3o1NriAJWsLY2J9WF6hgdnWM@vger.kernel.org",
        "X-Gm-Message-State": "AOJu0YxVfyx218wj0MjKryabB0e5nAQAbxOYsrBAyLlXjHOxQDkWaBW3\n\tFLf2urdNwZ0fAt1/xh4t1Eljc9Saavl5ljzJGw9ASksddfradbG+H8tq",
        "X-Gm-Gg": "AeBDiev2a6Guc9utx1k1JkEi3Gor4Z50b6TSNbVnNLjp3V58IeQxWoB9rHhc4D9gyK3\n\t8aKpOjoFLJ5zg7V7Wu/HTzA8YvC8FcoAsnaRMUc2ToMWHZQjL5xjXhgyA74ZXdCQfDewGFgM5RF\n\tE3z6LpF47Za0jiIP+A43t9nBKMhwkHTClaZ1EyaWa7Yad0xXQPlkmvI9PWaQCnO4RuODJ5pv2yY\n\t+cxNBEHD5BDDj6TJwJotRZSw3bcunIlhMWPugBJAb82KyLY7cUGyXn/8Ou4Rz6ycFxcTrF8lFRI\n\tapb1LfC+rHuYs1Bv/XWDTuTUGp/ybC5p4pD8/L9eB/nDnpj08xb3gO931YTpiVmxgUuxrjKdEau\n\tYYh/nw8gWKhdV09bnq1n9cxDFxE3hX5HmhsO8nlESd1C4kPdHmJV3hsScbELPhk2T9Mv1OU3SGu\n\tjIXIHEgRsNjpryrucTkuw6P4+cMRZ9bAEE6/rH/VloexmtUvX7L9b8d486VeF7ua2Gt0PfOF4l8\n\tI6Nydi+MWTefMAkeF79Q7yGh1l1WGGTDppvwRVBSTG+7LdPXN4tVQ==",
        "X-Received": "by 2002:ad4:5d42:0:b0:8ac:a4f9:da7a with SMTP id\n 6a1803df08f44-8b0280f7e88mr4451406d6.32.1776375452536;\n        Thu, 16 Apr 2026 14:37:32 -0700 (PDT)",
        "From": "Michael Bommarito <michael.bommarito@gmail.com>",
        "To": "Steve French <sfrench@samba.org>,\n\tNamjae Jeon <linkinjeon@kernel.org>,\n\tlinux-cifs@vger.kernel.org",
        "Cc": "Paulo Alcantara <pc@manguebit.org>,\n\tRonnie Sahlberg <ronniesahlberg@gmail.com>,\n\tShyam Prasad N <sprasad@microsoft.com>,\n\tTom Talpey <tom@talpey.com>,\n\tBharath SM <bharathsm@microsoft.com>,\n\tstable@vger.kernel.org",
        "Subject": "[PATCH] smb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO\n path",
        "Date": "Thu, 16 Apr 2026 17:37:16 -0400",
        "Message-ID": "<20260416213716.3118443-1-michael.bommarito@gmail.com>",
        "X-Mailer": "git-send-email 2.53.0",
        "Precedence": "bulk",
        "X-Mailing-List": "linux-cifs@vger.kernel.org",
        "List-Id": "<linux-cifs.vger.kernel.org>",
        "List-Subscribe": "<mailto:linux-cifs+subscribe@vger.kernel.org>",
        "List-Unsubscribe": "<mailto:linux-cifs+unsubscribe@vger.kernel.org>",
        "MIME-Version": "1.0",
        "Content-Transfer-Encoding": "8bit"
    },
    "content": "Another client side from my clanker. smb2_ioctl_query_info() has two\nresponse-copy branches: PASSTHRU_FSCTL and the default QUERY_INFO path.\nThe FSCTL branch validates that the server-reported output length fits\nwithin the response iov:\n\n    if (qi.input_buffer_length > 0 &&\n        le32_to_cpu(io_rsp->OutputOffset) + qi.input_buffer_length\n        > rsp_iov[1].iov_len)\n\nThe QUERY_INFO branch has no equivalent check:\n\n    qi_rsp = (struct smb2_query_info_rsp *)rsp_iov[1].iov_base;\n    if (le32_to_cpu(qi_rsp->OutputBufferLength) < qi.input_buffer_length)\n        qi.input_buffer_length = le32_to_cpu(qi_rsp->OutputBufferLength);\n    ...\n    copy_to_user(pqi + 1, qi_rsp->Buffer, qi.input_buffer_length)\n\nA malicious server can set OutputBufferLength larger than the actual\nresponse, causing copy_to_user to read past the slab allocation into\nadjacent kernel heap.\n\nReproduced under UML + KASAN by constructing a 73-byte response\n(sizeof(struct smb2_query_info_rsp) + 1) with OutputBufferLength=2,\nforcing a read 1 byte past the allocation:\n\n  BUG: KASAN: slab-out-of-bounds in _nfs4_do_fsinfo\n  Read of size 1 at addr ... by task mount.nfs4/219\n\nConfirmed rejection without splat after patch applied.\n\nAdd the same bounds check used by the FSCTL branch.\n\nFixes: 5242fcb706cb (\"cifs: fix bi-directional fsctl passthrough calls\")\nCc: stable@vger.kernel.org\nAssisted-by: Claude:claude-opus-4-6\nSigned-off-by: Michael Bommarito <michael.bommarito@gmail.com>\n---\n fs/smb/client/smb2ops.c | 6 ++++++\n 1 file changed, 6 insertions(+)",
    "diff": "diff --git a/fs/smb/client/smb2ops.c b/fs/smb/client/smb2ops.c\nindex 509fcea28a42..de10077320e1 100644\n--- a/fs/smb/client/smb2ops.c\n+++ b/fs/smb/client/smb2ops.c\n@@ -1783,6 +1783,12 @@ smb2_ioctl_query_info(const unsigned int xid,\n \t\tqi_rsp = (struct smb2_query_info_rsp *)rsp_iov[1].iov_base;\n \t\tif (le32_to_cpu(qi_rsp->OutputBufferLength) < qi.input_buffer_length)\n \t\t\tqi.input_buffer_length = le32_to_cpu(qi_rsp->OutputBufferLength);\n+\t\tif (qi.input_buffer_length > 0 &&\n+\t\t    sizeof(struct smb2_query_info_rsp) + qi.input_buffer_length\n+\t\t    > rsp_iov[1].iov_len) {\n+\t\t\trc = -EFAULT;\n+\t\t\tgoto out;\n+\t\t}\n \t\tif (copy_to_user(&pqi->input_buffer_length,\n \t\t\t\t &qi.input_buffer_length,\n \t\t\t\t sizeof(qi.input_buffer_length))) {\n",
    "prefixes": []
}