[PATCH 5.15 098/128] ksmbd: fix error code in ndr_read_int32()

From: Greg Kroah-Hartman
Date: Mon Dec 27 2021 - 10:47:42 EST


From: Dan Carpenter <dan.carpenter@xxxxxxxxxx>

commit ef399469d9ceb9f2171cdd79863f9434b9fa3edc upstream.

This is a failure path and it should return -EINVAL instead of success.
Otherwise it could result in the caller using uninitialized memory.

Fixes: 303fff2b8c77 ("ksmbd: add validation for ndr read/write functions")
Cc: stable@xxxxxxxxxxxxxxx # v5.15
Acked-by: Namjae Jeon <linkinjeon@xxxxxxxxxx>
Signed-off-by: Dan Carpenter <dan.carpenter@xxxxxxxxxx>
Signed-off-by: Steve French <stfrench@xxxxxxxxxxxxx>
Signed-off-by: Greg Kroah-Hartman <gregkh@xxxxxxxxxxxxxxxxxxx>
---
fs/ksmbd/ndr.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)

--- a/fs/ksmbd/ndr.c
+++ b/fs/ksmbd/ndr.c
@@ -148,7 +148,7 @@ static int ndr_read_int16(struct ndr *n,
static int ndr_read_int32(struct ndr *n, __u32 *value)
{
if (n->offset + sizeof(__u32) > n->length)
- return 0;
+ return -EINVAL;

if (value)
*value = le32_to_cpu(*(__le32 *)ndr_get_field(n));