Re: [PATCH v3 0/2] smb: client: fix dangling pointer in DFS target hints
ChenXiaoSong <[email protected]> Tue, 4 Aug 2026 08:48:14 +0800
| Newsgroups | org.kernel.vger.linux-kernel,org.kernel.vger.linux-cifs |
|---|---|
| Message-ID | <[email protected]> |
It seems that patch 02 should be applied first. Looks good to me. Reviewed-by: ChenXiaoSong <[email protected]> On 7/25/26 06:01, Fredric Cover wrote: > This series addresses a Use-After-Free bug where ce->tgthint was left > pointing to freed memory after free_tgts() was called. > > To fix this, Patch 1 hardens the DFS cache readers against ce->tgthint > being NULL. Also, Patch 1 hardens callers of get_tgt_name(), which > returns an error pointer when ce->tgthint is NULL. > > Patch 2 clears ce->tgthint in free_tgts(), eliminating the dangling > pointer. > > v2 -> v3: > - Resent series with proper thread structure and subject headers. > > v1 -> v2: > - Addressed automated review by Sashiko: > https://sashiko.dev/#/patchset/20260724023539.1596955-1-fredric.cover.lkernel%40gmail.com > - Split into a 2-patch series to harden readers against NULL and > ERR_PTR target hints. > > Fredric Cover (2): > smb: client: harden DFS cache against invalid target hints > smb: client: clear ce->tgthint in free_tgts() > > fs/smb/client/dfs_cache.c | 33 ++++++++++++++++++++++++++------- > 1 file changed, 26 insertions(+), 7 deletions(-) > -- ChenXiaoSong <[email protected]> Chinese Homepage: https://chenxiaosong.com English Homepage: https://chenxiaosong.com/en