[PATCH 0/4] smb: server: Clear sensitive data before freeing it

Thomas Huth <[email protected]>
Newsgroups org.kernel.vger.linux-cifs,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
Sensitive data like keys that are stored in stack-local arrays could be
leaked via the stack to the calling functions, or via the heap when using
only normal kfree() functions.

It's good security practice to clear sensitive data on the stack first
with memzero_explicit() before leaving the context, and to use
kfree_sensitive() for data that is returned to the heap.

Disclaimer: The spots that need clearing have been identified with AI,
but the patches have been created manually (for double-checking whether
the findings really make sense). Anyway, I'm not very familiar with the
smb code, so please review carefully. Thanks!

Thomas Huth (4):
  smb: server: Clear sensitive stack and heap data in auth.c
  smb: server: Make sure that passkey is not leaked on the heap in
    user_config.c
  smb: server: Free session data with kfree_sensitive() to avoid leaking
    of data
  smb: server: Free sensitive connection data with kfree_sensitive()

 fs/smb/server/auth.c              | 11 +++++++++--
 fs/smb/server/connection.c        |  4 ++--
 fs/smb/server/mgmt/user_config.c  |  6 +++---
 fs/smb/server/mgmt/user_session.c |  4 ++--
 4 files changed, 16 insertions(+), 9 deletions(-)

-- 
2.55.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.