Re: [PATCH] smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2

Namjae Jeon <[email protected]>
Newsgroups org.kernel.vger.linux-cifs,org.kernel.vger.stable
Message-ID <CAKYAXd_3303gs1eYXMYbceGdm=iF4BsX0v-6sLHbdhW7CUe8Wg@mail.gmail.com>
On Thu, Aug 13, 2026 at 11:40 AM Frank Sorenson <[email protected]> wrote:
>
> When a valid primary TRANSACT2 response has been received (mid->resp_buf
> set, mid->multiRsp true) and a subsequent secondary response causes
> cifs_check_trans2() to return false -- either because the SMB header is
> invalid (malformed != 0) or because check2ndT2() rejects the PDU --
> handle_mid() overwrites mid->resp_buf with the new buffer (leaking the
> primary buffer) and, because mid->multiRsp is set, skips the
> server->smallbuf/bigbuf NULL-out.  When the user thread frees
> mid->resp_buf, server->smallbuf or server->bigbuf is left dangling; the
> demux thread reuses it for the next packet, resulting in a use-after-free.
>
> Combine both early-exit conditions and, when mid->multiRsp is already
> set, abort the pending transaction inline: set multiEnd, call
> dequeue_mid() with malformed=true, and return true so handle_mid() exits
> without touching mid->resp_buf or the server buffer pointers.
>
> Fixes: 316cf94a910f ("CIFS: Move trans2 processing to ops struct")
> Cc: [email protected] # cifs_check_trans2() is in smb1ops.c on kernels < 7.0
> Signed-off-by: Frank Sorenson <[email protected]>
Will apply it to #for-next.
Thanks!
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.