[PATCH v2 0/2] smb: client: fix dangling pointer in DFS target hints
Fredric Cover <[email protected]> Fri, 24 Jul 2026 14:44:33 -0700
| Newsgroups | org.kernel.vger.linux-cifs,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <[email protected]> |
This series addresses a Use-After-Free bug where ce->tgthint was left pointing to freed memory after free_tgts() was called. To fix this, Patch 1 hardens the DFS cache readers against ce->tgthint being NULL. Also, Patch 1 hardens callers of get_tgt_name(), which returns an error pointer when ce->tgthint is NULL. Patch 2 clears ce->tgthint in free_tgts(), eliminating the dangling pointer. v1 -> v2: - Addressed automated review by Sashiko: https://sashiko.dev/#/patchset/20260724023539.1596955-1-fredric.cover.lkernel%40gmail.com Split into a 2-patch series to harden readers against NULL and ERR_PTR target hints so that clearing ce->tgthint does not cause NULL pointer dereferences. Fredric Cover (2): smb: client: harden DFS cache against invalid target hints smb: client: clear ce->tgthint in free_tgts() fs/smb/client/dfs_cache.c | 33 ++++++++++++++++++++++++++------- 1 file changed, 26 insertions(+), 7 deletions(-) -- 2.53.0