In the Linux kernel, the following vulnerability has been resolved: smb/client: validate new EOF for insert range smb3_insert_range() does
위협 신호 · CVSS · EPSS · KEV
이론적 심각도 점수
예측 데이터 없음
실측 악용 기록 없음
계획된 패치 주기 내 조치(60일 이내)
CVSS 벡터 · 메트릭
CVSS 벡터 정보 없음
상세 설명
In the Linux kernel, the following vulnerability has been resolved:
smb/client: validate new EOF for insert range
smb3_insert_range() does not check if the new file size
(i_size + len) is valid. This allows FALLOC_FL_INSERT_RANGE to bypass
RLIMIT_FSIZE, exceed s_maxbytes, or produce a size outside the loff_t
range.
Use check_add_overflow() to calculate the new EOF. Validate it with
inode_newsize_ok() before modifying the file.
Reproducer, using a file on a CIFS mount:
1bash -c ' 2 FILE=/mnt/cifs/repro 3 4 trap "" SIGXFSZ 5 ulimit -f 3072 # RLIMIT_FSIZE = 3 MiB 6 7 # A regular write is stopped at 3 MiB. 8 dd if=/dev/zero of="$FILE" bs=1M count=4 status=none 9 stat -c "size after write: %s" "$FILE"10 11 # Insert 2 MiB into a 2 MiB file.12 truncate -s 2M "$FILE"13 fallocate -i -o 0 -l 2M "$FILE"14 stat -c "size after insert: %s" "$FILE"15'Before this change, the regular write stops at the 3 MiB limit, but
insert range grows the file to 4 MiB:
1dd: error writing '/mnt/cifs/repro': File too large 2size after write: 3145728 3size after insert: 4194304After this change, insert range also fails at the limit and leaves the
2 MiB file unchanged:
1dd: error writing '/mnt/cifs/repro': File too large 2size after write: 3145728 3fallocate: fallocate failed: File too large 4size after insert: 2097152AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.
참고 자료 4
링크 내용 불러오는 중…