Re: [PATCH] smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2
Namjae Jeon <[email protected]>
| Newsgroups | org.kernel.vger.linux-cifs,org.kernel.vger.stable |
|---|---|
| Message-ID | <CAKYAXd_3303gs1eYXMYbceGdm=iF4BsX0v-6sLHbdhW7CUe8Wg@mail.gmail.com> |
On Thu, Aug 13, 2026 at 11:40 AM Frank Sorenson <[email protected]> wrote: > > When a valid primary TRANSACT2 response has been received (mid->resp_buf > set, mid->multiRsp true) and a subsequent secondary response causes > cifs_check_trans2() to return false -- either because the SMB header is > invalid (malformed != 0) or because check2ndT2() rejects the PDU -- > handle_mid() overwrites mid->resp_buf with the new buffer (leaking the > primary buffer) and, because mid->multiRsp is set, skips the > server->smallbuf/bigbuf NULL-out. When the user thread frees > mid->resp_buf, server->smallbuf or server->bigbuf is left dangling; the > demux thread reuses it for the next packet, resulting in a use-after-free. > > Combine both early-exit conditions and, when mid->multiRsp is already > set, abort the pending transaction inline: set multiEnd, call > dequeue_mid() with malformed=true, and return true so handle_mid() exits > without touching mid->resp_buf or the server buffer pointers. > > Fixes: 316cf94a910f ("CIFS: Move trans2 processing to ops struct") > Cc: [email protected] # cifs_check_trans2() is in smb1ops.c on kernels < 7.0 > Signed-off-by: Frank Sorenson <[email protected]> Will apply it to #for-next. Thanks!