1. Aug 01, 2022
    • Namjae Jeon's avatar
      ksmbd: fix use-after-free bug in smb2_tree_disconect · cf6531d9
      Namjae Jeon authored
      smb2_tree_disconnect() freed the struct ksmbd_tree_connect,
      but it left the dangling pointer. It can be accessed
      again under compound requests.
      
      This bug can lead an oops looking something link:
      
      [ 1685.468014 ] BUG: KASAN: use-after-free in ksmbd_tree_conn_disconnect+0x131/0x160 [ksmbd]
      [ 1685.468068 ] Read of size 4 at addr ffff888102172180 by task kworker/1:2/4807
      ...
      [ 1685.468130 ] Call Trace:
      [ 1685.468132 ]  <TASK>
      [ 1685.468135 ]  dump_stack_lvl+0x49/0x5f
      [ 1685.468141 ]  print_report.cold+0x5e/0x5cf
      [ 1685.468145 ]  ? ksmbd_tree_conn_disconnect+0x131/0x160 [ksmbd]
      [ 1685.468157 ]  kasan_report+0xaa/0x120
      [ 1685.468194 ]  ? ksmbd_tree_conn_disconnect+0x131/0x160 [ksmbd]
      [ 1685.468206 ]  __asan_report_load4_noabort+0x14/0x20
      [ 1685.468210 ]  ksmbd_tree_conn_disconnect+0x131/0x160 [ksmbd]
      [ 1685.468222 ]  smb2_tree_disconnect+0x175/0x250 [ksmbd]
      [ 1685.468235 ]  handle_ksmbd_work+0x30e/0x1020 [ksmbd]
      [ 1685.468247 ]  process_one_work+0x778/0x11c0
      [ 1685.468251 ]  ? _raw_spin_lock_irq+0x8e/0xe0
      [ 1685.468289 ]  worker_thread+0x544/0x1180
      [ 1685.468293 ]  ? __cpuidle_text_end+0x4/0x4
      [ 1685.468297 ]  kthread+0x282/0x320
      [ 1685.468301 ]  ? process_one_work+0x11c0/0x11c0
      [ 1685.468305 ]  ? kthread_complete_and_exit+0x30/0x30
      [ 1685.468309 ]  ret_from_fork+0x1f/0x30
      
      Fixes: e2f34481
      
       ("cifsd: add server-side procedures for SMB3")
      Cc: stable@vger.kernel.org
      Reported-by: zdi-disclosures@trendmicro.com # ZDI-CAN-17816
      Signed-off-by: default avatarNamjae Jeon <linkinjeon@kernel.org>
      Reviewed-by: default avatarHyunchul Lee <hyc.lee@gmail.com>
      Signed-off-by: default avatarSteve French <stfrench@microsoft.com>
      cf6531d9
    • Namjae Jeon's avatar
      ksmbd: fix memory leak in smb2_handle_negotiate · aa7253c2
      Namjae Jeon authored
      The allocated memory didn't free under an error
      path in smb2_handle_negotiate().
      
      Fixes: e2f34481
      
       ("cifsd: add server-side procedures for SMB3")
      Cc: stable@vger.kernel.org
      Reported-by: zdi-disclosures@trendmicro.com # ZDI-CAN-17815
      Signed-off-by: default avatarNamjae Jeon <linkinjeon@kernel.org>
      Reviewed-by: default avatarHyunchul Lee <hyc.lee@gmail.com>
      Signed-off-by: default avatarSteve French <stfrench@microsoft.com>
      aa7253c2
    • Namjae Jeon's avatar
      ksmbd: fix racy issue while destroying session on multichannel · af7c39d9
      Namjae Jeon authored
      
      
      After multi-channel connection with windows, Several channels of
      session are connected. Among them, if there is a problem in one channel,
      Windows connects again after disconnecting the channel. In this process,
      the session is released and a kernel oop can occurs while processing
      requests to other channels. When the channel is disconnected, if other
      channels still exist in the session after deleting the channel from
      the channel list in the session, the session should not be released.
      Finally, the session will be released after all channels are disconnected.
      
      Signed-off-by: default avatarNamjae Jeon <linkinjeon@kernel.org>
      Reviewed-by: default avatarHyunchul Lee <hyc.lee@gmail.com>
      Signed-off-by: default avatarSteve French <stfrench@microsoft.com>
      af7c39d9
    • Namjae Jeon's avatar
      ksmbd: use wait_event instead of schedule_timeout() · a14c5738
      Namjae Jeon authored
      
      
      ksmbd threads eating masses of cputime when connection is disconnected.
      If connection is disconnected, ksmbd thread waits for pending requests
      to be processed using schedule_timeout. schedule_timeout() incorrectly
      is used, and it is more efficient to use wait_event/wake_up than to check
      r_count every time with timeout.
      
      Signed-off-by: default avatarNamjae Jeon <linkinjeon@kernel.org>
      Reviewed-by: default avatarHyunchul Lee <hyc.lee@gmail.com>
      Signed-off-by: default avatarSteve French <stfrench@microsoft.com>
      a14c5738
  2. Jul 27, 2022
  3. Jul 25, 2022
  4. Jul 18, 2022
  5. Jul 17, 2022
  6. Jul 16, 2022