From: Shuangpeng Bai Date: Sun, 2 Aug 2026 00:48:09 +0000 (-0400) Subject: smb: client: Fix use-after-free in cifs_try_adding_channels() X-Git-Url: http://git.ipfire.org/gitweb/?a=commitdiff_plain;h=4986410316b1ae0e63c6ce418e4eb196723626e7;p=thirdparty%2Fkernel%2Flinux.git smb: client: Fix use-after-free in cifs_try_adding_channels() cifs_try_adding_channels() takes a temporary reference to an interface before dropping iface_lock. If cifs_ses_add_channel() fails, it drops that reference and then increments iface->weight_fulfilled. A concurrent interface list refresh can remove the list reference while channel creation is in progress. In that case, the failure-path kref_put() releases the last reference and frees iface. Updating weight_fulfilled afterward then accesses freed memory. Increment weight_fulfilled before dropping the temporary reference, keeping iface alive for the final access. Fixes: 6aac002bcfd5 ("cifs: failure to add channel on iface should bump up weight") Cc: stable@vger.kernel.org Signed-off-by: Shuangpeng Bai Signed-off-by: Steve French --- diff --git a/fs/smb/client/sess.c b/fs/smb/client/sess.c index de2012cc9cf3..7cf7dd104f7c 100644 --- a/fs/smb/client/sess.c +++ b/fs/smb/client/sess.c @@ -233,9 +233,9 @@ int cifs_try_adding_channels(struct cifs_ses *ses) cifs_dbg(VFS, "failed to open extra channel on iface:%pIS rc=%d\n", &iface->sockaddr, rc); - kref_put(&iface->refcount, release_iface); /* failure to add chan should increase weight */ iface->weight_fulfilled++; + kref_put(&iface->refcount, release_iface); continue; }