]> www.infradead.org Git - users/dwmw2/linux.git/commit
ksmbd: fix use-after-free in ksmbd_sessions_deregister()
authorNamjae Jeon <linkinjeon@kernel.org>
Sat, 22 Mar 2025 00:20:19 +0000 (09:20 +0900)
committerSteve French <stfrench@microsoft.com>
Fri, 28 Mar 2025 00:12:00 +0000 (19:12 -0500)
commit15a9605f8d69dc85005b1a00c31a050b8625e1aa
tree36fd995c8de5af1afea34cbe610ac4836e353064
parent6955bfef8f2b5b2f4e35577b708967bd986d3aa3
ksmbd: fix use-after-free in ksmbd_sessions_deregister()

In multichannel mode, UAF issue can occur in session_deregister
when the second channel sets up a session through the connection of
the first channel. session that is freed through the global session
table can be accessed again through ->sessions of connection.

Cc: stable@vger.kernel.org
Reported-by: Norbert Szetei <norbert@doyensec.com>
Tested-by: Norbert Szetei <norbert@doyensec.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
fs/smb/server/mgmt/user_session.c