]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
ksmbd: defer destroy_previous_session() until after NTLM authentication
authorJames Montgomery <james_montgomery@disroot.org>
Fri, 3 Jul 2026 19:26:41 +0000 (15:26 -0400)
committerSteve French <stfrench@microsoft.com>
Wed, 22 Jul 2026 14:54:10 +0000 (09:54 -0500)
In ntlm_authenticate(), destroy_previous_session() is called using a
user pointer resolved from the client-supplied NTLM blob username field
before the NTLMv2 response is validated. An authenticated attacker can
set the NTLM blob username to match a victim account and set
PreviousSessionId to the victim's session ID; destroy_previous_session()
destroys the victim's session while ksmbd_decode_ntlmssp_auth_blob()
subsequently rejects the request with -EPERM.

Move destroy_previous_session() and the prev_id assignment to after
ksmbd_decode_ntlmssp_auth_blob() returns success and use sess->user
rather than the pre-authentication lookup result. This matches the
ordering already used by krb5_authenticate(), where
destroy_previous_session() is called only after
ksmbd_krb5_authenticate() returns success.

Fixes: e2f34481b24d ("cifsd: add server-side procedures for SMB3")
Cc: stable@vger.kernel.org
Link: https://lore.kernel.org/linux-cifs/20260702155449.3639773-1-james_montgomery@disroot.org/
Signed-off-by: James Montgomery <james_montgomery@disroot.org>
Acked-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
fs/smb/server/smb2pdu.c

index d54b714cc36cebfded4b3e6928f40a2d50102742..c1ba5e01aa7fa24e19f2e8c3ac7d16067a86e3df 100644 (file)
@@ -1717,11 +1717,6 @@ static int ntlm_authenticate(struct ksmbd_work *work,
                return -EPERM;
        }
 
-       /* Check for previous session */
-       prev_id = le64_to_cpu(req->PreviousSessionId);
-       if (prev_id && prev_id != sess->id)
-               destroy_previous_session(conn, user, prev_id);
-
        if (sess->state == SMB2_SESSION_VALID) {
                /*
                 * Reuse session if anonymous try to connect
@@ -1761,6 +1756,10 @@ static int ntlm_authenticate(struct ksmbd_work *work,
                }
        }
 
+       prev_id = le64_to_cpu(req->PreviousSessionId);
+       if (prev_id && prev_id != sess->id)
+               destroy_previous_session(conn, sess->user, prev_id);
+
        /*
         * If session state is SMB2_SESSION_VALID, We can assume
         * that it is reauthentication. And the user/password