]> www.infradead.org Git - users/jedix/linux-maple.git/commit
ksmbd: fix use-after-free in kerberos authentication
authorSean Heelan <seanheelan@gmail.com>
Sat, 19 Apr 2025 18:59:28 +0000 (19:59 +0100)
committerSteve French <stfrench@microsoft.com>
Fri, 25 Apr 2025 23:22:01 +0000 (18:22 -0500)
commite86e9134e1d1c90a960dd57f59ce574d27b9a124
tree1b2ffb54bb6f6dad6a2917b7c59c3acc03fb62e0
parenta1f46c99d9ea411f9bf30025b912d881d36fc709
ksmbd: fix use-after-free in kerberos authentication

Setting sess->user = NULL was introduced to fix the dangling pointer
created by ksmbd_free_user. However, it is possible another thread could
be operating on the session and make use of sess->user after it has been
passed to ksmbd_free_user but before sess->user is set to NULL.

Cc: stable@vger.kernel.org
Signed-off-by: Sean Heelan <seanheelan@gmail.com>
Acked-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
fs/smb/server/auth.c
fs/smb/server/smb2pdu.c