Re: [PATCH] smb/server: fix use-after-free in ksmbd_conn_transport_destroy()

Namjae Jeon <[email protected]>
Newsgroups org.kernel.vger.linux-cifs
Message-ID <CAKYAXd_wCGpRuiigfnN+QCRntkCkMYOQf++fXiYMme2WDh0ssA@mail.gmail.com>
On Thu, Aug 13, 2026 at 7:41 PM ChenXiaoSong
<[email protected]> wrote:
>
> From: ChenXiaoSong <[email protected]>
>
> Reproducer (Link[1]):
>
>   1. Build kernel with CONFIG_KASAN=y
>   2. server: systemctl start ksmbd
>   3. client: mount -t cifs //localhost/export /mnt
>   4. client: umount /mnt
>   5. server: modprobe -r ksmbd
>
> The error message is as follows:
>
>   ==================================================================
>   BUG: KASAN: slab-use-after-free in proc_remove+0x3e/0x80
>   Read of size 8 at addr ffff88810654e098 by task modprobe/785
>   ...
>   Call Trace:
>    <TASK>
>    __dump_stack+0x19/0x30
>    dump_stack_lvl+0x49/0x60
>    print_address_description+0x7b/0x200
>    print_report+0x5b/0x70
>    kasan_report+0xed/0x130
>    __asan_report_load8_noabort+0x18/0x20
>    proc_remove+0x3e/0x80
>    ksmbd_conn_transport_destroy+0x2b/0x320 [ksmbd]
>    cleanup_module+0x33/0xe00 [ksmbd]
>    __se_sys_delete_module+0x276/0x400
>    __x64_sys_delete_module+0x5f/0x70
>    x64_sys_call+0x2675/0x3030
>    do_syscall_64+0xf0/0x3b0
>    entry_SYSCALL_64_after_hwframe+0x76/0x7e
>   RIP: 0033:0x7f5b56d2b02b
>   ...
>    </TASK>
>
>   Allocated by task 159:
>    kasan_save_track+0x2f/0x70
>    kasan_save_alloc_info+0x40/0x50
>    __kasan_slab_alloc+0x52/0x70
>    kmem_cache_alloc_noprof+0x168/0x3e0
>    __proc_create+0x20b/0x710
>    proc_create_single_data+0x78/0x150
>    ksmbd_proc_create+0x24/0x30 [ksmbd]
>    ksmbd_conn_transport_init+0x4f/0x80 [ksmbd]
>    server_ctrl_handle_work+0x64/0x2c0 [ksmbd]
>    process_scheduled_works+0x788/0xec0
>    worker_thread+0x894/0xc10
>    kthread+0x2e5/0x3c0
>    ret_from_fork+0x168/0x4f0
>    ret_from_fork_asm+0x1a/0x30
>
>   Freed by task 785:
>    kasan_save_track+0x2f/0x70
>    kasan_save_free_info+0x4a/0x60
>    __kasan_slab_free+0x47/0x70
>    kmem_cache_free+0x122/0x410
>    pde_put+0xfd/0x160
>    remove_proc_subtree+0x365/0x540
>    proc_remove+0x6a/0x80
>    ksmbd_proc_cleanup+0x1f/0x60 [ksmbd]
>    cleanup_module+0x18/0xe00 [ksmbd]
>    __se_sys_delete_module+0x276/0x400
>    __x64_sys_delete_module+0x5f/0x70
>    x64_sys_call+0x2675/0x3030
>    do_syscall_64+0xf0/0x3b0
>    entry_SYSCALL_64_after_hwframe+0x76/0x7e
>   ==================================================================
>
> Reported-by: Kyenghwan Hwang <[email protected]>
> Link[1]: https://lore.kernel.org/linux-cifs/[email protected]/
> Signed-off-by: ChenXiaoSong <[email protected]>
Applied it to #ksmbd-for-next-next.
Thanks!
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.