]> git.ipfire.org Git - thirdparty/kernel/stable-queue.git/commitdiff
5.10-stable patches
authorGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Tue, 22 Apr 2025 10:29:37 +0000 (12:29 +0200)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Tue, 22 Apr 2025 10:29:37 +0000 (12:29 +0200)
added patches:
smb-client-fix-potential-uaf-in-cifs_stats_proc_show.patch

queue-5.10/series
queue-5.10/smb-client-fix-potential-uaf-in-cifs_stats_proc_show.patch [new file with mode: 0644]

index 32fd358329fa943aec1d2100578fdfa7dd542091..e195712bf0487ff0d0270536b80f024b0aa2e6e4 100644 (file)
@@ -160,3 +160,4 @@ smb-client-fix-potential-uaf-in-cifs_debug_files_proc_show.patch
 smb-client-fix-use-after-free-bug-in-cifs_debug_data_proc_show.patch
 cifs-fix-uaf-in-cifs_demultiplex_thread.patch
 smb-client-fix-potential-deadlock-when-releasing-mids.patch
+smb-client-fix-potential-uaf-in-cifs_stats_proc_show.patch
diff --git a/queue-5.10/smb-client-fix-potential-uaf-in-cifs_stats_proc_show.patch b/queue-5.10/smb-client-fix-potential-uaf-in-cifs_stats_proc_show.patch
new file mode 100644 (file)
index 0000000..748fba7
--- /dev/null
@@ -0,0 +1,38 @@
+From 0865ffefea197b437ba78b5dd8d8e256253efd65 Mon Sep 17 00:00:00 2001
+From: Paulo Alcantara <pc@manguebit.com>
+Date: Tue, 2 Apr 2024 16:33:56 -0300
+Subject: smb: client: fix potential UAF in cifs_stats_proc_show()
+
+From: Paulo Alcantara <pc@manguebit.com>
+
+commit 0865ffefea197b437ba78b5dd8d8e256253efd65 upstream.
+
+Skip sessions that are being teared down (status == SES_EXITING) to
+avoid UAF.
+
+Cc: stable@vger.kernel.org
+Signed-off-by: Paulo Alcantara (Red Hat) <pc@manguebit.com>
+Signed-off-by: Steve French <stfrench@microsoft.com>
+[ cifs_debug.c was moved from fs/cifs to fs/smb/client since
+  38c8a9a52082 ("smb: move client and server files to common directory fs/smb").
+  The cifs_ses_exiting() was introduced to cifs_debug.c since
+  ca545b7f0823 ("smb: client: fix potential UAF in cifs_debug_files_proc_show()")
+  which has been sent to upstream already. ]
+Signed-off-by: Jianqi Ren <jianqi.ren.cn@windriver.com>
+Signed-off-by: He Zhe <zhe.he@windriver.com>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ fs/cifs/cifs_debug.c |    2 ++
+ 1 file changed, 2 insertions(+)
+
+--- a/fs/cifs/cifs_debug.c
++++ b/fs/cifs/cifs_debug.c
+@@ -595,6 +595,8 @@ static int cifs_stats_proc_show(struct s
+               list_for_each(tmp2, &server->smb_ses_list) {
+                       ses = list_entry(tmp2, struct cifs_ses,
+                                        smb_ses_list);
++                      if (cifs_ses_exiting(ses))
++                              continue;
+                       list_for_each(tmp3, &ses->tcon_list) {
+                               tcon = list_entry(tmp3,
+                                                 struct cifs_tcon,