Re: [PATCH v2 0/2] smb: client: fix dangling pointer in DFS target hints

Namjae Jeon <[email protected]>
Newsgroups org.kernel.vger.linux-kernel,org.kernel.vger.linux-cifs
Message-ID <CAKYAXd_uABp-cX+DgKKr4YvxUTM21X2KD=twffUpRt=harWCXQ@mail.gmail.com>
On Sat, Jul 25, 2026 at 6:47 AM Fredric Cover
<[email protected]> wrote:
>
> This series addresses a Use-After-Free bug where ce->tgthint was left
> pointing to freed memory after free_tgts() was called.
>
> To fix this, Patch 1 hardens the DFS cache readers against ce->tgthint
> being NULL. Also, Patch 1 hardens callers of get_tgt_name(), which
> returns an error pointer when ce->tgthint is NULL.
>
> Patch 2 clears ce->tgthint in free_tgts(), eliminating the dangling
> pointer.
>
> v1 -> v2:
>  - Addressed automated review by Sashiko:
>    https://sashiko.dev/#/patchset/20260724023539.1596955-1-fredric.cover.lkernel%40gmail.com
>    Split into a 2-patch series to harden readers against NULL and
>    ERR_PTR target hints so that clearing ce->tgthint does not cause
>    NULL pointer dereferences.
>
> Fredric Cover (2):
>   smb: client: harden DFS cache against invalid target hints
>   smb: client: clear ce->tgthint in free_tgts()
I will apply v3 patch-set to #for-next.
Thanks!
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.