From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f53.google.com (mail-wm1-f53.google.com [209.85.128.53]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 15C3C3D45FA for ; Wed, 19 Aug 2026 09:09:10 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.53 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787130552; cv=none; b=YREzmHq+AiVPsHagvzx1/Y+hu4vrxvyz4rlAmtdLqBS3MSaN3GURB92gCYMHhwUyhRnCZ3XZ6V/ykNFOD+X+8h/lKIz2lM1rsm/OM4Y3+P2loSzVy0MK+tkLt5lyxwPosHxvF8D2oTiH/s96S83TI0OSo2g3L1L4QhB4hY6+Nwk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787130552; c=relaxed/simple; bh=JmodvTaXREPGXLwMR9LszkkZbcM/nBfmW4O3QqESnnI=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=SC+d20n+4IhTVyD9Z0f0Fx+ATy8r3kb2tecqjlGQYqRPAemYwJVNA6Wi6o3ws56lyxRIkUkdaDWOjI2WmtXoD0tGD28GyTZvKhtsaAoesSkVnhXyMgikjn1exhiZn5trgMXJgA4s0Dbz0qTLgmc9W+/LsSz30UAfMYXe+1ZWvhA= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=VY4fFc3b; arc=none smtp.client-ip=209.85.128.53 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="VY4fFc3b" Received: by mail-wm1-f53.google.com with SMTP id 5b1f17b1804b1-499acf0fb55so2066945e9.3 for ; Wed, 19 Aug 2026 02:09:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787130549; x=1787735349; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=2UbNZOStqr4QXwJzGGjS9zVa1/oBME6yib0prBXIAgY=; b=VY4fFc3bkNdvdLxFuHBewVTsk/T8O8zgIoXwrsnfWGEjU1IgaLpIj9ZnwMJoM66qv+ GdSaAwTLOD2IkOLmJBZERfikhZO0ZnbmQiD6qteDWaW6q7Crq8/Z7yXte9BiUs0I/olZ yt1VDfzV5v3s6EHSXBLpPk6nBIy0vG2lPTgU2PpxrlDbqpKlAWYiLm3LgajRGim+GfUt MczVWzt4kN/fzS7zbAeKpfov1kGMyhWyicHeRztqv6ZUJIdFocxvHtIyHbinR/Rfukfr KmQSOltgcAdrJT3/g2t9CyH5UzLWPa7Ndx5g+NtXFS8SD3kymdMepIEpzqrDbdoP7xw8 oEcg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787130549; x=1787735349; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=2UbNZOStqr4QXwJzGGjS9zVa1/oBME6yib0prBXIAgY=; b=mQcgZeLeCKPCTHKLzoLBSUJfthgFZrQJbyYGBqFfKHS6RoJCPQ2P6xOcV5ug/xUqdW mqbrWCmaDj3d8nx3ZwOcC3WBE9nErVcveCiY5yNdS1KC8+rTh7o5axatzZbAzcgVi7h+ WFPb7s9BZBYlAXfw3/CAOXC0uHT9AEu0xvxhFQypPQQXDOyQtNIJcjb32eDebGqo4D0z yn/yX4p4QX5HCDq7LUg90zI1xrfh2EBll3l9jfjLXcuv3Wn9Y1Wn5HAef8UkQs1WJpzK gt68J/lRetB9CE+K1JxItYt0tPtW0/XJGcCS10DRnYexABwsGPu87RFTAemYZdFI+klc n5yw== X-Gm-Message-State: AOJu0YyCUItDAn6G2lTfku8nWsFu0mByUbmDUtnEuJssRD1eaL1KphYQ 1FICmXIrSc8VkIYjbLu/KfX85jvzWmYL1gBFMyVVPFeOYU8WiJDTqXH7 X-Gm-Gg: AR+sD10y9ZxRofEFDbExyA+n5qOXnyrrnI4Pkcbc1bKX6aLbwUnh2r0uzMxehphB1PB EcIPAYjvCDexgsRo1uQu+wbAzyq1WUfwg19lIZMqkL1dwwD4nF+rCnJ8pO5deaQzRDPKrN+2d3R GPbI9FB2wgbv2Uiv4oZ2T55nyeLCMbzO9gN9XrPYiCwWkWODJkio54mcxOUIrlfVikrtEEk+ZP3 KsjtrvclDorVEwCopPqhvoOOaB+z0hfB04FmVilnWGAGfLlqQna6cd2ZGnA7nkMsZJP0OHHjXud /6eiwLZ7vmZR04JxIlV3vP1eRG8Wutr67Td4L/vRFAZB5Tf2khUS7iVitdYyiABFwAaA9mIjGtX FaSUt/2dzmqGWqLC3wjGd8eszAvK6CG3ijujOLPdkbjpFZctrYjVRLXC+e5W2H1PnFPXJJvV8hM I6MUturUuukquF24OSq7FOOn3xMefC36+Ny3K88tC4TOf77on8bW2R8pnK1Xnt1pk/aD/NN6WMv p3tbLo= X-Received: by 2002:a05:600c:a414:b0:499:adb5:e7b2 with SMTP id 5b1f17b1804b1-499adb5e7d2mr17727365e9.11.1787130549116; Wed, 19 Aug 2026 02:09:09 -0700 (PDT) Received: from SurHub.localdomain ([196.188.112.82]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499a9e78496sm50286265e9.2.2026.08.19.02.09.07 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 19 Aug 2026 02:09:08 -0700 (PDT) From: Abdifatah Suruur To: linux-cifs@vger.kernel.org Cc: linux-kernel@vger.kernel.org, linkinjeon@kernel.org, sfrench@samba.org, senozhatsky@chromium.org, tom@talpey.com Subject: [PATCH] ksmbd: fix use-after-free of lease table in smb2_lease_break_noti() Date: Wed, 19 Aug 2026 12:09:05 +0300 Message-ID: <20260819090905.12448-1-suruurism@gmail.com> X-Mailer: git-send-email 2.53.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit smb2_lease_break_noti() redirects v2 lease break notifications to the client lease channel by reading lease->l_lb->conn. The lease table is linked into the global lease_table_list and destroyed by destroy_lease_table() on connection teardown, which unlinks it and kfree()s it under write_lock(&lease_list_lock). The break path dereferences lease->l_lb and lease->l_lb->conn without holding lease_list_lock, so when the owning connection is torn down concurrently (e.g. the client disconnects while another connection's open triggers a lease break), the table can be freed between the load and the dereference. This is a use-after-free read of struct lease_table; the stale conn pointer is then passed to ksmbd_conn_releasing() and ksmbd_conn_get(), corrupting a refcount on memory that may have been reallocated. Take a conn reference and perform the lease-table lookup under read_lock(&lease_list_lock), matching the lock discipline of find_same_lease_key() and lookup_lease_in_table(), and transfer the reference to the async work item instead of re-taking it. Fixes: 2145945feb2c2 ("ksmbd: route v2 lease breaks on the client lease channel") Cc: stable@vger.kernel.org Signed-off-by: Abdifatah Suruur --- fs/smb/server/oplock.c | 16 +++++++++------- 1 file changed, 9 insertions(+), 7 deletions(-) diff --git a/fs/smb/server/oplock.c b/fs/smb/server/oplock.c index 79787099afdc6..ac21583cb6222 100644 --- a/fs/smb/server/oplock.c +++ b/fs/smb/server/oplock.c @@ -1007,20 +1007,27 @@ static int smb2_lease_break_noti(struct oplock_info *opinfo, bool wait_ack, struct lease *lease = opinfo->o_lease; int ret = 0; - conn = READ_ONCE(opinfo->conn); + conn = ksmbd_conn_get(READ_ONCE(opinfo->conn)); + read_lock(&lease_list_lock); if (lease->version == 2 && lease->l_lb && lease->l_lb->conn && - !ksmbd_conn_releasing(lease->l_lb->conn)) - conn = lease->l_lb->conn; + !ksmbd_conn_releasing(lease->l_lb->conn)) { + ksmbd_conn_put(conn); + conn = ksmbd_conn_get(lease->l_lb->conn); + } + read_unlock(&lease_list_lock); if (!conn) return ksmbd_invalidate_durable_fd(opinfo->fid); work = ksmbd_alloc_work_struct(); - if (!work) + if (!work) { + ksmbd_conn_put(conn); return -ENOMEM; + } br_info = kmalloc_obj(struct lease_break_info, KSMBD_DEFAULT_GFP); if (!br_info) { ksmbd_free_work_struct(work); + ksmbd_conn_put(conn); return -ENOMEM; } @@ -1036,7 +1043,7 @@ static int smb2_lease_break_noti(struct oplock_info *opinfo, bool wait_ack, memcpy(br_info->lease_key, lease->lease_key, SMB2_LEASE_KEY_SIZE); work->request_buf = (char *)br_info; - work->conn = ksmbd_conn_get(conn); + work->conn = conn; work->sess = opinfo->sess; ksmbd_conn_r_count_inc(conn);