Re: [PATCH v3 0/2] smb: client: fix dangling pointer in DFS target hints

ChenXiaoSong <[email protected]> Tue, 4 Aug 2026 08:48:14 +0800
Newsgroups org.kernel.vger.linux-cifs,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
It seems that patch 02 should be applied first.

Looks good to me.

Reviewed-by: ChenXiaoSong <[email protected]>

On 7/25/26 06:01, Fredric Cover wrote:
> This series addresses a Use-After-Free bug where ce->tgthint was left
> pointing to freed memory after free_tgts() was called.
> 
> To fix this, Patch 1 hardens the DFS cache readers against ce->tgthint
> being NULL. Also, Patch 1 hardens callers of get_tgt_name(), which
> returns an error pointer when ce->tgthint is NULL.
> 
> Patch 2 clears ce->tgthint in free_tgts(), eliminating the dangling
> pointer.
> 
> v2 -> v3:
>   - Resent series with proper thread structure and subject headers.
> 
> v1 -> v2:
>   - Addressed automated review by Sashiko:
>     https://sashiko.dev/#/patchset/20260724023539.1596955-1-fredric.cover.lkernel%40gmail.com
>   - Split into a 2-patch series to harden readers against NULL and
>     ERR_PTR target hints.
> 
> Fredric Cover (2):
>    smb: client: harden DFS cache against invalid target hints
>    smb: client: clear ce->tgthint in free_tgts()
> 
>   fs/smb/client/dfs_cache.c | 33 ++++++++++++++++++++++++++-------
>   1 file changed, 26 insertions(+), 7 deletions(-)
> 

-- 
ChenXiaoSong <[email protected]>
Chinese Homepage: https://chenxiaosong.com
English Homepage: https://chenxiaosong.com/en